5.8
CVE-2015-1638
- EPSS 12.72%
- Veröffentlicht 14.04.2015 20:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2012 Version r2 SwEdition datacenter
Microsoft ≫ Windows Server 2012 Version r2 SwEdition essentials
Microsoft ≫ Windows Server 2012 Version r2 SwEdition standard
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 12.72% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://www.securitytracker.com/id/1032115
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-040