5

CVE-2014-6331

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Active Directory Federation Services Version 2.0
   Microsoft ≫ Windows 2008 Update sp2 HwPlatform x64
   Microsoft ≫ Windows 2008 Update sp2 HwPlatform x86
   Microsoft ≫ Windows 2008 Version r2 Update sp2 HwPlatform x64
Microsoft ≫ Active Directory Federation Services Version 3.0
   Microsoft ≫ Windows Server 2012 Version r2 SwPlatform x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.32% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx
Vendor Advisory
http://www.securityfocus.com/bid/70938
http://www.securitytracker.com/id/1031195
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-077