CVE-2020-1055

Summary

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs.

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows 10 Version 180910.0.17763.0 < publicationaffected
MicrosoftWindows 10 Version 180910.0.0 < publicationaffected
MicrosoftWindows 10 Version 1903 for 32-bit Systems10.0.0 < publicationaffected
MicrosoftWindows 10 Version 1903 for ARM64-based Systems10.0.0 < publicationaffected
MicrosoftWindows 10 Version 1903 for x64-based Systems10.0.0 < publicationaffected
MicrosoftWindows 10 Version 190910.0.0 < publicationaffected
MicrosoftWindows Server 201910.0.17763.0 < publicationaffected
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0 < publicationaffected
MicrosoftWindows Server, version 1903 (Server Core installation)10.0.0 < publicationaffected
MicrosoftWindows Server, version 1909 (Server Core installation)10.0.0 < publicationaffected

Weaknesses

  • Spoofing

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References