CVE-2024-21381: Microsoft Azure Active Directory B2C Spoofing Vulnerability
Published Feb 13, 2024
·Updated
Microsoft Azure Active Directory B2C Spoofing Vulnerability
Affected Software
3 affected componentsFixes available
Microsoft Azure Active Directory B2C
Microsoft Azure Active Directory
Microsoft Azure Active Directory B2C
Remediation
Event History
Feb 13, 2024
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21381?
CVE-2024-21381 is classified as a moderate severity spoofing vulnerability that affects Microsoft Azure Active Directory B2C.
2
How do I fix CVE-2024-21381?
To fix CVE-2024-21381, ensure that you are using the latest version of Microsoft Azure Active Directory B2C and follow the recommended patching instructions.
3
What kind of impact does CVE-2024-21381 have?
CVE-2024-21381 could potentially allow an attacker to spoof authentication in Microsoft Azure Active Directory B2C.
4
Which versions of Microsoft Azure Active Directory B2C are affected by CVE-2024-21381?
CVE-2024-21381 affects all versions of Microsoft Azure Active Directory B2C prior to applying the relevant patches.
5
Is there a workaround for CVE-2024-21381?
Currently, Microsoft recommends applying the latest security updates as the primary method for mitigating CVE-2024-21381, with no specific workarounds provided.