CVE-2021-40456HighCVSS 5.3

Windows AD FS Security Feature Bypass Vulnerability

Published
October 12, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What kind of security feature could be bypassed by successfully exploiting this vulnerability? This vulnerability could allow an attacker to bypass ADFS BannedIPList entries for WS-Trust workflows.

🎯 Affected products6

  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server, version 2004 (Server Core installation)
  • Windows Server, version 20H2 (Server Core Installation)

✅ Remediation

KB5006672 (Security Update) — fixed build 10.0.17763.2237 KB5006699 (Security Update) — fixed build 10.0.20348.288 KB5006670 (Security Update) — fixed build 10.0.19041.1288 KB5006670 (Security Update) — fixed build 10.0.19042.1288

🔗 References (6)