Executive brief
Microsoft Active Directory Federation Services (AD FS), which provides single sign-on access to applications, contains a security flaw that could allow an attacker to perform spoofing. An attacker with high-level permissions could use this vulnerability to trick users into interacting with malicious content, potentially leading to unauthorized actions or information disclosure. This could impact the integrity of the authentication portal and the trust users place in corporate login pages.
Technical details
A cross-site scripting (XSS) vulnerability exists in Active Directory Federation Services (AD FS) due to improper neutralization of input during web page generation. An attacker with high privileges (PR:H) can exploit this over the network by tricking a user into interacting with a malicious link or page (UI:R). Successful exploitation allows the attacker to execute arbitrary script in the context of the user's browser, facilitating spoofing or limited information disclosure. The vulnerability affects multiple versions of Windows and Windows Server, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 10 Version 1607 < 10.0.14393.9339
- Microsoft Windows 10 Version 1809 < 10.0.17763.9020
- Microsoft Windows Server 2012 < 6.2.9200.26226
- Microsoft Windows Server 2012 R2 < 6.3.9600.23291
- Microsoft Windows Server 2016 < 10.0.14393.9339
- Microsoft Windows Server 2019 < 10.0.17763.9020
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD