CVE-2019-1006: High severity microsoft .net framework 4 vulnerability
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1006?
The severity of CVE-2019-1006 is high with a CVSS score of 7.5.
Which software is affected by CVE-2019-1006?
The affected software includes Microsoft .NET Framework versions 2.0 SP2, 3.0 SP2, and 3.5, as well as Microsoft Identitymodel version 7.0.0.
How does the authentication bypass vulnerability in CVE-2019-1006 work?
The vulnerability allows signing of SAML tokens with arbitrary symmetric keys, bypassing authentication in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF).
Is Windows 10 vulnerable to CVE-2019-1006?
No, Windows 10 is not vulnerable to CVE-2019-1006.
How can I fix CVE-2019-1006?
Apply the necessary security updates provided by Microsoft to fix the authentication bypass vulnerability in CVE-2019-1006.