First published: Tue Apr 13 2021(Updated: )
Azure AD Web Sign-in Security Feature Bypass Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Windows 10 | ||
Windows 10 | =20h2 | |
Windows 10 | =1803 | |
Windows 10 | =1809 | |
Windows 10 | =1909 | |
Windows 10 | =2004 | |
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27092 is a vulnerability in Azure AD Web Sign-in that allows for security feature bypass.
The vulnerability affects Microsoft Windows 10 versions 1803, 1809, 1909, 2004, and 20H2, as well as Windows Server 2016 and Windows Server 2019.
CVE-2021-27092 has a severity rating of 9.8, which is considered critical.
To fix CVE-2021-27092, Microsoft has provided a security update. Apply the latest updates from Microsoft to protect against this vulnerability.
You can find more information about CVE-2021-27092 on the Microsoft Security Guidance Advisory page: [CVE-2021-27092](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27092)