Vulnerability Name: | CVE-2009-2509 (CCN-54426) | ||||||||
Assigned: | 2009-12-08 | ||||||||
Published: | 2009-12-08 | ||||||||
Updated: | 2019-02-26 | ||||||||
Summary: | Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability." | ||||||||
CVSS v3 Severity: | 8.0 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-2509 Source: CCN Type: SA37542 Windows Active Directory Federation Services Two Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS09-070 Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726) Source: CCN Type: BID-37214 Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability Source: CERT Type: US Government Resource TA09-342A Source: MS Type: UNKNOWN MS09-070 Source: XF Type: UNKNOWN win-adfs-code-execution(54426) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6441 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |