ZeroHour

CVE-2019-1006

CVSS 3.0
7.5 high
EPSS
6%p93
Published
()
Modified
Description

An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.

Vendors
microsoft
Products
.net framework, identitymodel, sharepoint enterprise server, sharepoint foundation, sharepoint server, windows 10, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.