CVE-2021-41361HighCVSS 5.4

Active Directory Federation Server Spoofing Vulnerability

Published
October 12, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? The ADFS (Active Directory Federation Services) services are vulnerable during the logout redirect request to cross-site scripting of the post logout redirect URI. An attacker who successfully exploited this vulnerability could leave an application using this ADFS library vulnerable to common XSS attacks.

🎯 Affected products8

  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server, version 2004 (Server Core installation)
  • Windows Server, version 20H2 (Server Core Installation)

✅ Remediation

KB5006672 (Security Update) — fixed build 10.0.17763.2237 KB5006699 (Security Update) — fixed build 10.0.20348.288 KB5006670 (Security Update) — fixed build 10.0.19041.1288 KB5006669 (Security Update) — fixed build 10.0.14393.4704

🔗 References (7)