PT-2009-4915 · Microsoft · Windows Server 2008+2
Published
2009-12-09
·
Updated
2019-02-26
·
CVE-2009-2508
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2
Active Directory Federation Services (ADFS) in Microsoft Windows Server 2008 Gold and SP2
Description
The single sign-on implementation in Active Directory Federation Services (ADFS) does not properly remove credentials at the end of a network session. This allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache.
Recommendations
For Microsoft Windows Server 2003 SP2, update the system to remove the vulnerability.
For Microsoft Windows Server 2008 Gold and SP2, update the system to remove the vulnerability.
As a temporary workaround, consider clearing the browser's cache after each use to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Active Directory Federation Services
Windows Server 2003
Windows Server 2008