PT-2018-13754 · Microsoft · Adfs+1

Alphan Yavas

·

Published

2018-09-18

·

Updated

2025-11-29

·

CVE-2018-16794

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft ADFS versions prior to 4.0 on Windows Server 2016 and previous
Description The issue concerns a Server-Side Request Forgery (SSRF) vulnerability. It can be exploited via the txtBoxEmail parameter in the "/adfs/ls" API endpoint.
Recommendations For Microsoft ADFS versions prior to 4.0 on Windows Server 2016 and previous, as a temporary workaround, consider restricting access to the /adfs/ls API endpoint to minimize the risk of exploitation. Avoid using the txtBoxEmail parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16794

Affected Products

Adfs
Windows Server 2016