The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability."
Base Score: 4.3
Impact Score: 2.9
Exploitability Score: 8.6
Base Score: 3.7
Impact Score: 1.4
Exploitability Score: 2.2
|99312||Windows 8.1 and Windows Server 2012 R2 April 2017 Security Updates||Nessus||Windows : Microsoft Bulletins|
|99288||KB4015583: Windows 10 Version 1703 April 2017 Cumulative Update||Nessus||Windows : Microsoft Bulletins|
|99286||KB4015217: Windows 10 1607 April 2017 Cumulative Update||Nessus||Windows : Microsoft Bulletins|