VYPR
High severity7.5NVD Advisory· Published Feb 10, 2016· Updated May 6, 2026

CVE-2016-0037

CVE-2016-0037

Description

The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability."

Affected products

3
  • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:datacenter:*:*:*+ 2 more
    • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:datacenter:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:essentials:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:standard:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.