Lucene search

K
cve[email protected]CVE-2009-2508
HistoryDec 09, 2009 - 6:30 p.m.

CVE-2009-2508

2009-12-0918:30:00
CWE-255
web.nvd.nist.gov
25
active directory federation services
adfs
microsoft
windows server
cve-2009-2508
single sign on
spoofing
vulnerability

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.1 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

31.4%

The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser’s cache, aka “Single Sign On Spoofing in ADFS Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_server_2008sp2x32
OR
microsoftwindows_server_2008sp2x64

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6.1 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

31.4%