Microsoft Active Directory Federation Services是美国微软(Microsoft)公司的一个在Windows Server操作系统上运行的软件组件。它为用户提供对无法通过Active Directory ( AD )使用集成Windows身份验证 (IWA) 的系统和应用程序的单点登录访问。 microsoft Active Directory Federation Services存在安全特征问题漏洞。以下产品和版本受到影响:Windows Server 201
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows Server 2016 | 10.0.14393.0< 10.0.14393.4530 |
affected |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0< 10.0.14393.4530 |
affected |
| Microsoft | Windows Server 2019 | 10.0.17763.0< 10.0.17763.2061 |
affected |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0< 10.0.17763.2061 |
affected |
| Microsoft | Windows Server version 2004 | 10.0.0< 10.0.19041.1110 |
affected |
| Microsoft | Windows Server version 20H2 | 10.0.0< 10.0.19042.1110 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows Server 2016 | 10.0.14393.0 ~ 10.0.14393.4530 | - |
|
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 ~ 10.0.14393.4530 | - |
|
| Microsoft | Windows Server 2019 | 10.0.17763.0 ~ 10.0.17763.2061 | - |
|
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 ~ 10.0.17763.2061 | - |
|
| Microsoft | Windows Server version 2004 | 10.0.0 ~ 10.0.19041.1110 | - |
|
| Microsoft | Windows Server version 20H2 | 10.0.0 ~ 10.0.19042.1110 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-34473 | 9.1 CRITICAL | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-34523 | 9.0 CRITICAL | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-33749 | 8.8 HIGH | Windows DNS Snap-in Remote Code Execution Vulnerability |
| CVE-2021-34508 | 8.8 HIGH | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2021-33756 | 8.8 HIGH | Windows DNS Snap-in Remote Code Execution Vulnerability |
| CVE-2021-34494 | 8.8 HIGH | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2021-33780 | 8.8 HIGH | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2021-33750 | 8.8 HIGH | Windows DNS Snap-in Remote Code Execution Vulnerability |
| CVE-2021-33752 | 8.8 HIGH | Windows DNS Snap-in Remote Code Execution Vulnerability |
| CVE-2021-34525 | 8.8 HIGH | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2021-33767 | 8.2 HIGH | Open Enclave SDK Elevation of Privilege Vulnerability |
| CVE-2021-34469 | 8.2 HIGH | Microsoft Office Security Feature Bypass Vulnerability |
| CVE-2021-34492 | 8.1 HIGH | Windows Certificate Spoofing Vulnerability |
| CVE-2021-34520 | 8.1 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2021-33781 | 8.1 HIGH | Azure AD Security Feature Bypass Vulnerability |
| CVE-2021-33786 | 8.1 HIGH | Windows LSA Security Feature Bypass Vulnerability |
| CVE-2021-33746 | 8.0 HIGH | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2021-33754 | 8.0 HIGH | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2021-34470 | 8.0 HIGH | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-34474 | 8.0 HIGH | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability |
Showing top 20 of 90 CVEs. View all on vendor page → →
No comments yet