CVE-2015-1638
medium · 5.8Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
5.8
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2015-04-14
Published
AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2012 | r2 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-1638