Active directory federation services information disclosure vulnerability - MS15-040ID: oval:org.secpod.oval:def:24081 | Date: (C)2015-04-15 (M)2021-09-11 |
Class: PATCH | Family: windows |
The host is missing an important security update according to Microsoft security bulletin, MS15-040. The update is required to fix an information disclosure vulnerability. A flaw is present in the application, which fails to properly log off an user. Successful exploitation could allow attackers to discover information to which an AD FS user has access.
Platform: |
Microsoft Windows Server 2012 R2 |
Product: |
Microsoft Active Directory Federation Services |