MS13-066: Vulnerability in Active Directory Federation Services Could Allow Information Disclosure (2873872)

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The remote Windows host is affected by an information disclosure
vulnerability.

Description :

The remote Windows host is affected by an unspecified vulnerability in
the Active Directory Federation Services (AD FS) that may allow an
attacker to obtain the AD FS instance account information.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms13-066

Solution :

Microsoft has released a set of patches for Windows Server 2003 R2,
2008, 2008 R2, and 2012.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 3.7
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 69331 ()

Bugtraq ID: 61672

CVE ID: CVE-2013-3185