CVE-2014-6331
Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 20.32% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/active directory federation services
- Source
- secure@microsoft.com
References
- http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspxVendor Advisory
- http://www.securityfocus.com/bid/70938
- http://www.securitytracker.com/id/1031195
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-077
- http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspxVendor Advisory
- http://www.securityfocus.com/bid/70938
- http://www.securitytracker.com/id/1031195
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-077
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.