Information disclosure in Windows Server - CVE-2017-0043
Published: March 14, 2017
Windows Server
Detailed vulnerability description
The vulnerability exists due to a flaw in Windows Active Directory Federation Services (ADFS) when handling XML External Entities. A remote authenticated attacker can send a specially crafted request to the ADFS service and gain access to important data.
Successful exploitation of this vulnerability results in information disclosure.