| CVE Number | Vulnerability | Product | Severity | Date | 
|---|---|---|---|---|
| MS14-077 | Vulnerability in Active Directory Federation Services Could Allow Information Disclosure (3003381) | Windows Server | Important | 12-11-2014 | 
Technical Information
Brief overview of the risk:
This security update resolves a privately reported vulnerability in Active Directory Federation Services (AD FS). The vulnerability could allow information disclosure if a user leaves their browser open after logging off from an application, and an attacker reopens the application in the browser immediately after the user has logged off.
Detailed Information on the risk:
An information disclosure vulnerability exists when Active Directory Federation Services (AD FS) fails to properly log off a user. The vulnerability could allow unintentional information disclosure. Microsoft received information about this vulnerability through coordinated vulnerability disclosure.
Further information on this exploit is available at : MS14-077
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2012
Windows Server 2012 R2
Affected Software
Windows Server 2008 for 32-bit Systems Service Pack 2Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2012
Windows Server 2012 R2
 
 
					