Check: 2015-B-0072
Windows 2012 IAVM:
2015-B-0072
(in version v1 r30)
Title
Microsoft Active Directory Federation Services Privilege Escalation Vulnerability (MS15-062) (Cat I impact)
Discussion
Microsoft has released a security bulletin addressing a vulnerability in Active Directory Federation Services. Active Directory Federation Services (AD FS) is a standards-based service that allows the secure sharing of identity information between trusted business partners (known as a federation) across an extranet. To exploit this vulnerability, an attacker would submit a specially crafted URL or entice a user to visit a malicious site. If successfully exploited, the attacker would gain access to system information with elevated privileges.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-60963
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |