First published: Mon Jul 15 2019(Updated: )
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework 4 | =2.0-sp2 | |
Microsoft .NET Framework 4 | =3.0-sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft .NET Framework 4 | =3.5 | |
Windows 10 | ||
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Windows 10 | =1803 | |
Microsoft Windows | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1803 | |
Microsoft .NET Framework 4 | =4.7.2 | |
Windows 10 | =1809 | |
Microsoft Windows Server 2019 | ||
Microsoft .NET Framework 4 | =4.8 | |
Windows 10 | =1903 | |
Microsoft .NET Framework 4 | =3.5.1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft .NET Framework 4 | =4.5.2 | |
Microsoft Windows RT | ||
Microsoft .NET Framework 4 | =4.6 | |
Microsoft .NET Framework 4 | =4.6.1 | |
Microsoft .NET Framework 4 | =4.6.2 | |
Microsoft .NET Framework 4 | =4.7 | |
Microsoft .NET Framework 4 | =4.7.1 | |
Microsoft Identity Model | =7.0.0 | |
Microsoft SharePoint Enterprise Server 2016 | =2013-sp1 | |
Microsoft SharePoint Enterprise Server 2016 | =2016 | |
Microsoft SharePoint Foundation 2013 | =2010-sp2 | |
Microsoft SharePoint Foundation 2013 | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2019 | |
Windows 10 | ||
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Windows 10 | =1803 | |
Windows 10 | =1809 | |
Windows 10 | =1903 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-1006 is high with a CVSS score of 7.5.
The affected software includes Microsoft .NET Framework versions 2.0 SP2, 3.0 SP2, and 3.5, as well as Microsoft Identitymodel version 7.0.0.
The vulnerability allows signing of SAML tokens with arbitrary symmetric keys, bypassing authentication in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF).
No, Windows 10 is not vulnerable to CVE-2019-1006.
Apply the necessary security updates provided by Microsoft to fix the authentication bypass vulnerability in CVE-2019-1006.