First published: Wed Nov 14 2018(Updated: )
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1709 | |
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8547 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2018-8547, ensure that the affected AD FS customization properly sanitizes web requests.
CVE-2018-8547 affects multiple versions of Microsoft Windows 10, Windows 8.1, Windows RT, and Windows Server 2012, 2016, and 2019.
CVE-2018-8547 is a cross-site scripting (XSS) vulnerability.
Yes, if exploited, CVE-2018-8547 could allow attackers to execute arbitrary scripts in the context of a user's session.