CVE Vulnerabilities

CVE-2015-1638

Published: Apr 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka Active Directory Federation Services Information Disclosure Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Windows_server_2012Microsoftr2 (including)r2 (including)

References