CVE-2018-8340: Medium severity microsoft windows server vulnerability
A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows Server 2012 R2, Windows 10 Servers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8340?
CVE-2018-8340 has a severity rating of important as it allows attackers to bypass multi-factor authentication.
How do I fix CVE-2018-8340?
To fix CVE-2018-8340, apply the latest security updates provided by Microsoft for affected versions of Windows Server.
What systems are affected by CVE-2018-8340?
CVE-2018-8340 affects Windows Server 2016, Windows Server 2012 R2, and various Windows 10 Server versions.
Can CVE-2018-8340 lead to unauthorized access?
Yes, CVE-2018-8340 can potentially allow unauthorized access due to the bypass of multi-factor authentication.
Is multi-factor authentication sufficient if CVE-2018-8340 is present?
No, relying solely on multi-factor authentication is insufficient if CVE-2018-8340 is present due to the vulnerability.