CVE-2021-27092: Azure AD Web Sign-in Security Feature Bypass Vulnerability
Published Apr 13, 2021
·Updated
Azure AD Web Sign-in Security Feature Bypass Vulnerability
Affected Software
10 affected components
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Remediation
Event History
Apr 13, 2021
CVE Published
07:32 PM
Data Sourced
07:32 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-27092?
CVE-2021-27092 is a vulnerability in Azure AD Web Sign-in that allows for security feature bypass.
2
Which software is affected by CVE-2021-27092?
The vulnerability affects Microsoft Windows 10 versions 1803, 1809, 1909, 2004, and 20H2, as well as Windows Server 2016 and Windows Server 2019.
3
What is the severity of CVE-2021-27092?
CVE-2021-27092 has a severity rating of 9.8, which is considered critical.
4
How can I fix CVE-2021-27092?
To fix CVE-2021-27092, Microsoft has provided a security update. Apply the latest updates from Microsoft to protect against this vulnerability.
5
Where can I find more information about CVE-2021-27092?
You can find more information about CVE-2021-27092 on the Microsoft Security Guidance Advisory page: [CVE-2021-27092](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27092)