CVE-2019-1273 — Active Directory Federation Services XSS Vulnerability
Executive Summary
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the ADFS site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that ADFS error handling properly sanitizes error messages.
Overview
CVSS Vector
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1803 for 32-bit Systems | 4516058 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1803 for ARM64-based Systems | 4516058 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1803 for x64-based Systems | 4516058 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 4512578 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 4512578 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1809 for x64-based Systems | 4512578 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1903 for 32-bit Systems | 4515384 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1903 for ARM64-based Systems | 4515384 (Security Update) |
Important | Spoofing | Yes |
| Windows 10 Version 1903 for x64-based Systems | 4515384 (Security Update) |
Important | Spoofing | Yes |
| Windows Server 2019 | 4512578 (Security Update) |
Important | Spoofing | Yes |
| Windows Server 2019 (Server Core installation) | 4512578 (Security Update) |
Important | Spoofing | Yes |
| Windows Server, version 1803 (Server Core Installation) | 4516058 (Security Update) |
Important | Spoofing | Yes |
| Windows Server, version 1903 (Server Core installation) | 4515384 (Security Update) |
Important | Spoofing | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
4516058 |
Security Update | Yes |
4512578 |
Security Update | Yes |
4515384 |
Security Update | Yes |
Known Exploits
Acknowledgments
Johannes Gutenberg Universität-Mainz