MS15-062: Vulnerability in Active Directory Federation Services Could Allow Elevation of Privilege (3062577)

This script is Copyright (C) 2015-2017 Tenable Network Security, Inc.

Synopsis :

The remote Windows host is affected by a privilege escalation

Description :

The remote Windows host is affected by an XSS elevation of privilege
vulnerability in Active Directory Federation Services (AD FS) due to
improper sanitization of user-supplied input. A remote attacker can
exploit this by submitting a specially crafted URL to a target site,
resulting in the execution of malicious script code in the security
context of the user or the ability to conduct further cross-site
scripting attacks.

See also :

Solution :

Microsoft has released a set of patches for Windows Server 2008,
2008 R2, and 2012.

Risk factor :

Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 84060 ()

Bugtraq ID: 75023

CVE ID: CVE-2015-1757

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now