Azure Active Directory Connect
by Microsoft
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-8613 | Hig | 0.53 | 8.1 | 0.04 | Jun 29, 2017 | Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability." | ||
| CVE-2021-36949 | Hig | 0.46 | 7.1 | 0.01 | Aug 12, 2021 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | ||
| CVE-2019-1000 | Med | 0.35 | 5.3 | 0.02 | May 16, 2019 | An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to… |
- risk 0.53cvss 8.1epss 0.04
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."
- risk 0.46cvss 7.1epss 0.01
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.02
An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to…