CERT-In Vulnerability Note
CIVN-2014-0257
Microsoft Active Directory Federation Services Information Disclosure Vulnerability
Original Issue Date:November 12, 2014
Severity Rating: HIGH
Systems Affected
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2012 R2
- Windows Server 2012
Overview
A vulnerability has been reported in the Active Directory Federation Services (AD FS) component used by Microsoft Windows servers which could allow a remote attacker to access users information.
Description
An information disclosure vulnerability exists due to Active Directory Federation Services (AD FS) fails to properly log off a user. A remote attacker could exploit this vulnerability by reopening an application from which a user has recently logged off.
A successful exploitation could allow a remote attacker to access sensitive information, which could aid further attacks.
Solution
Apply appropriate updates as mentioned in Microsoft Security Bulletin
MS14-077
Vendor Information
Microsoft
https://technet.microsoft.com/en-US/library/security/MS14-077
References
Microsoft
https://technet.microsoft.com/en-US/library/security/MS14-077
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36277
Security Tracker
http://securitytracker.com/id/1031195
CVE Name
CVE-2014-6331
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|