← Back

CVE-2020-0837

nvd nist
Published: Sep 11, 2020Modified: Feb 23, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD (Secondary)

Description

<p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors.</p> <p>To exploit this vulnerability, an attacker could send a specially crafted authentication request.</p> <p>This security update corrects how ADFS handles multi-factor authentication requests.</p>

Affected (11)

3 products
Windows 10
Windows Server 2016
Windows Server 2019
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 1607
Version 1607
Version 1809
Version 1903
Version 1909
Version 2004
Microsoft
All versions
Version 1903
Version 1909
Version 2004
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.