CVE-2019-1006
EUVD-2019-959215.07.2019, 19:15
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | .net_framework | 2.0:sp2 |
| microsoft | .net_framework | 3.0:sp2 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | .net_framework | 3.5 |
| microsoft | .net_framework | 4.8 |
| microsoft | .net_framework | 3.5.1 |
| microsoft | .net_framework | 4.5.2 |
| microsoft | .net_framework | 4.6 |
| microsoft | .net_framework | 4.6 |
| microsoft | .net_framework | 4.6.1 |
| microsoft | .net_framework | 4.6.2 |
| microsoft | .net_framework | 4.6 |
| microsoft | .net_framework | 4.6.1 |
| microsoft | .net_framework | 4.6.2 |
| microsoft | .net_framework | 4.7 |
| microsoft | .net_framework | 4.7.1 |
| microsoft | .net_framework | 4.7.2 |
| microsoft | .net_framework | 4.8 |
| microsoft | identitymodel | 7.0.0 |
| microsoft | windows_10 | - |
| microsoft | windows_7 | - |
| microsoft | windows_8.1 | - |
| microsoft | windows_rt_8.1 | - |
| microsoft | windows_server_2008 | - |
| microsoft | windows_server_2012 | - |
| microsoft | windows_server_2016 | - |
| microsoft | windows_server_2019 | - |
𝑥
= Vulnerable software versions
Windows Releases
Platform | Version | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Windows 10 |
| ||||||||||||||||||||||||||||||
| Windows 7 |
| ||||||||||||||||||||||||||||||
| Windows 8.1 |
| ||||||||||||||||||||||||||||||
| Windows RT 8.1 |
| ||||||||||||||||||||||||||||||
| Windows Server |
| ||||||||||||||||||||||||||||||
| Windows Server 2008 |
| ||||||||||||||||||||||||||||||
| Windows Server 2008 R2 |
| ||||||||||||||||||||||||||||||
| Windows Server 2012 |
| ||||||||||||||||||||||||||||||
| Windows Server 2012 R2 |
| ||||||||||||||||||||||||||||||
| Windows Server 2016 |
| ||||||||||||||||||||||||||||||
| Windows Server 2019 |
|
Common Weakness Enumeration