4
CVSSv2

CVE-2018-8340

Published: 15/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows Server 2012 R2, Windows 10 Servers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2016 1803

microsoft windows server 2012 r2

microsoft windows server 2016 -

microsoft windows server 2016 1709

Github Repositories

windows-pentesting-resources Windows Pentesting Resources  : Fun with LDAP, Kerberos (and MSRPC) in AD Environments speakerdeckcom/ropnop/fun-with-ldap-kerberos-and-msrpc-in-ad-environments From XML External Entity to NTLM Domain Hashes techblogmediaservicenet/2018/02/from-xml-external-entity-to-ntlm-domain-hashes/ Windows Privilege Escalation Guide