CVE-2019-1006
—CVSS 3.0
7.5 high
EPSS
6%p93
Published
()
Modified
Description
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
- Vendors
- microsoft
- Products
- .net framework, identitymodel, sharepoint enterprise server, sharepoint foundation, sharepoint server, windows 10, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-295
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.