This script is Copyright (C) 2015-2017 Tenable Network Security, Inc.
The remote Windows host is affected by a privilege escalation
The remote Windows host is affected by an XSS elevation of privilege
vulnerability in Active Directory Federation Services (AD FS) due to
improper sanitization of user-supplied input. A remote attacker can
exploit this by submitting a specially crafted URL to a target site,
resulting in the execution of malicious script code in the security
context of the user or the ability to conduct further cross-site
See also :
Microsoft has released a set of patches for Windows Server 2008,
2008 R2, and 2012.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : false