CVE-2015-1638

Microsoft AD FS 3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032115

Scores

EPSS 0.1272
EPSS Percentile 95.9%

Details

CWE
CWE-264
Status published
Products (1)
microsoft/windows_server_2012 r2 (3 CPE variants)
Published Apr 14, 2015
Tracked Since Feb 18, 2026