CVE Published: 14/08/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: microsoft |
Vendor: Microsoft |
Product: Windows 10 Version 1703 Status : PUBLISHED
CVE-2019-1172 Description
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user\'s account.
To exploit the vulnerability, an attacker would have to trick a user into browsing to a specially crafted website, allowing the attacker to steal the user\'s token.
The security update addresses the vulnerability by correcting how MSA handles cookies.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C