Brute-force attack in Windows and Windows Server - CVE-2017-0159
Published: April 12, 2017
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a brute-force attack.
The vulnerability exists when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests. A remote attacker can brute-force account passwords.
Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to vulnerable system.