CVE-2009-2508 (CNNVD-200912-111)
中文标题:
Microsoft Windows Server Active Directory Federation Services信任管理漏洞
英文标题:
The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Window...
漏洞描述
中文描述:
Microsoft Windows Server 2003 SP2和Server 2008 Gold以及SP2中的Active Directory Federation Services (ADFS)的个别sign-on在网络会谈结束时执行不正确的移除资格,使现实最激烈的攻击者借助使用浏览器高速缓冲器的数据,获得使用同样网络浏览器的以前的用户的资格,称为"ADFS漏洞的Single Sign On Spoofing"
英文描述:
The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | windows_server_2003 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2008:*:*:x32:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:L/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2009-2508 |
2025-11-11 15:18:10 | 2025-11-11 07:33:02 |
| NVD | nvd_CVE-2009-2508 |
2025-11-11 14:53:01 | 2025-11-11 07:41:49 |
| CNNVD | cnnvd_CNNVD-200912-111 |
2025-11-11 15:09:07 | 2025-11-11 07:49:40 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200912-111
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.9
- cvss_vector: NOT_EXTRACTED -> AV:L/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']