CVE-2014-6331

Description

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka Active Directory Federation Services Information Disclosure Vulnerability.

Risk Information

Base Score
3.5
MODERATE
Vector
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
33.598

Associated Vulnerability

VulnerabilityOS Platform
ms14-077: vulnerability in active directory federation services could allow information disclosure: november 11, 2014 for Windows Server 2008 (KB3003381)Windows
ms14-077: vulnerability in active directory federation services could allow information disclosure: november 11, 2014 for Windows Server 2008 x64 Edition (KB3003381)Windows
ms14-077: vulnerability in active directory federation services could allow information disclosure: november 11, 2014 for Windows Server 2008 R2 x64 Edition (KB3003381)Windows
ms14-077: vulnerability in active directory federation services could allow information disclosure: november 11, 2014 for Windows Server 2012 (KB3003381)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-16524Security Update for Windows Server 2008 (KB3003381)
PATCH-16525Security Update for Windows Server 2008 x64 Edition (KB3003381)
PATCH-16526Security Update for Windows Server 2008 R2 x64 Edition (KB3003381)
PATCH-16527Security Update for Windows Server 2012 (KB3003381)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234