Vulnerability Name: | CVE-2017-0043 (CCN-122428) | ||||||||||||
Assigned: | 2016-09-09 | ||||||||||||
Published: | 2017-03-14 | ||||||||||||
Updated: | 2017-07-12 | ||||||||||||
Summary: | Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active Directory Federation Services Information Disclosure Vulnerability." | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.9 Low (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-0043 Source: CCN Type: Microsoft Security Bulletin MS17-019 Security Update for Active Directory Federation Services (4010320) Source: BID Type: Third Party Advisory, VDB Entry 96628 Source: CCN Type: BID-96628 Microsoft Windows CVE-2017-0043 XML External Entity Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1038018 Source: XF Type: UNKNOWN ms-adfs-cve20170043-info-disc(122428) Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0043 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |