Microsoft ADFS CVE-2019-0975 Security Feature Bypass Vulnerability

description-logoDescription

A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP addresses. This security update corrects how ADFS updates its list of banned IP addresses.

affected-products-logoAffected Applications

Windows Server 2016
Windows Server version 1903 (Server Core installation)
Windows Server version 1803 (Server Core Installation)
Windows Server 2019

CVE References

CVE-2019-0975