← All CVEs

CVE-2014-6331

medium · 5

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."

5
CVSS
20.3%
EPSS (exploit prob.)
97th
EPSS percentile
2014-11-11
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftactive_directory_federation_services2.1
microsoftwindows_server_2012all versions
microsoftactive_directory_federation_services2.0
microsoftwindows_2008all versions
microsoftwindows_2008all versions
microsoftwindows_2008r2
microsoftactive_directory_federation_services3.0
microsoftwindows_server_2012r2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-6331