vulnerability
Microsoft SharePoint: CVE-2019-1006: WCF/WIF SAML Token Authentication Bypass Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Jul 15, 2019 | May 15, 2023 | Aug 12, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Jul 15, 2019
Added
May 15, 2023
Modified
Aug 12, 2025
Description
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Solutions
microsoft-sharepoint-sharepoint_2016-kb4475520microsoft-sharepoint-sharepoint_2019-kb4475529
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.