← Back

CVE-2015-1638

nvd nist
Published: Apr 14, 2015Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."

Affected (3)

1 product
Windows Server 2012
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version r2
Version r2
Version r2

Related CWEs

Timeline

No history available yet.