Windows ADFS Security Feature Bypass Vulnerability - CVE-2021-33779ID: oval:org.secpod.oval:def:73763 | Date: (C)2021-07-14 (M)2024-01-02 |
Class: VULNERABILITY | Family: windows |
Windows ADFS Security Feature Bypass Vulnerability. This vulnerability relates to Primary Refresh Tokens which are usually stored in TPM. These tokens are usually used for SSO for Azure AD accounts. The tokens are not encrypted in a strong enough manner, and an administrator with access to a vulnerable system could extract and potentially decrypt the token for reuse until the token expires or is renewed.
Platform: |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2019 |
Microsoft Windows 10 |
Microsoft Windows Server |