CVE-2015-1638: Microsoft Windows Server 2012
Medium severity, CVSS 5.8. EPSS: 12.7% chance of exploitation in the next 30 days.
Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
Affected products
- Microsoft Windows Server 2012: version r2 only
Published 2015-04-14. Last modified 2026-06-17.