Brute-force attack in Microsoft Windows and Windows Server - CVE-2017-0159
Published: April 12, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a brute-force attack.
The vulnerability exists when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests. A remote attacker can brute-force account passwords.
Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to vulnerable system.
Affected software
Windows Server