MS13-066:Active Directory フェデレーション サービスの脆弱性により、情報漏えいが起こる (2873872)
2013年8月27日
危険度: : 高
CVE識別番号: CVE-2013-3185
概要
This security update resolves a privately reported vulnerability in Active Directory Federation Services (AD FS). The vulnerability could reveal information pertaining to the service account used by AD FS. An attacker could then attempt logons from outside the corporate network, which would result in account lockout of the service account used by AD FS if an account lockout policy has been configured. This would result in denial of service for all applications relying on the AD FS instance.
トレンドマイクロの対策
詳しい情報については以下のサイトをご参照ください。
対応方法
影響を受けるソフトウェア
- Active Directory Federation Services 2.1
- Active Directory Federation Services 2.0
- Active Directory Federation Services 1.x