← All CVEs

CVE-2015-1638

medium · 5.8

Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."

5.8
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2015-04-14
Published

AV:N/AC:M/Au:N/C:P/I:P/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftwindows_server_2012r2
microsoftwindows_server_2012r2
microsoftwindows_server_2012r2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-1638