PT-2021-3922 · Microsoft · Azure Active Directory Connect+1

Eyal Karni

+2

·

Published

2021-08-10

·

Updated

2023-12-28

·

CVE-2021-36949

CVSS v3.1

7.1

High

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Active Directory Connect Provisioning Agent and Azure Active Directory Connect (affected versions not specified)
Description The issue is related to deficiencies in the authentication mechanism of the Azure Active Directory Connect Provisioning Agent and Azure Active Directory Connect. Exploitation of this issue may allow an attacker to bypass security mechanisms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-04439
CVE-2021-36949

Affected Products

Azure Active Directory Connect
Azure Active Directory Connect Provisioning Agent