Microsoft ADFS CVE-2019-1126 Security Feature Bypass Vulnerability

description-logoDescription

A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy. To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory. This security update corrects how ADFS handles external authentication requests.

affected-products-logoAffected Applications

Windows Server 2016
Windows Server version 1903 (Server Core installation)
Windows Server version 1803 (Server Core Installation)
Windows Server 2012
Windows Server 2019

CVE References

CVE-2019-1126