Impact
Active Directory Federation Services generates web pages without properly neutralizing user supplied input, causing a cross‑site scripting flaw. This vulnerability can allow an attacker who already has authorization to the AD‑FS environment to display false or misleading content to users over a network. Although the vendor description does not detail specific attack outcomes, it is reasonable to infer that such spoofing could facilitate credential theft or other deceptive activities.
Affected Systems
The flaw affects Microsoft Windows 10 releases 1607 and 1809, as well as Windows Server 2012 through Windows Server 2025, including both full‑feature and Server Core installations. All listed Windows releases host AD‑FS components that are vulnerable.
Risk and Exploitability
CVSS score of 4.8 indicates moderate severity. The EPSS score of < 1% suggests real‑world exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker already has some level of authorization to the AD‑FS web interface; this attack would presumably be carried out from within the network or through a privileged remote session. Overall risk is moderate, but patching should be prioritized before widespread exploitation occurs.
OpenCVE Enrichment