PT-2020-3916 · Microsoft · Active Directory Federation Services+1

Christopher Currens

·

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-0837

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Active Directory Federation Services (ADFS) (affected versions not specified)
Description: An elevation of privilege issue exists due to improper handling of multi-factor authentication requests by Active Directory Federation Services (ADFS). This could allow an attacker to bypass some authentication factors by sending a specially crafted authentication request. The issue is related to errors in authentication.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2020-04309
CVE-2020-0837

Affected Products

Active Directory Federation Services
Windows