vulnerability
Microsoft Windows: CVE-2019-1126: ADFS Security Feature Bypass Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Jul 9, 2019 | Jul 9, 2019 | Sep 5, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jul 9, 2019
Added
Jul 9, 2019
Modified
Sep 5, 2025
Description
A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory.This security update corrects how ADFS handles external authentication requests., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0975.
Solutions
microsoft-windows-windows_server_2012_r2-kb4507457microsoft-windows-windows_server_2016-1607-kb4507460microsoft-windows-windows_server_2019-1809-kb4507469msft-kb4507453-8cedcb21-0200-433d-b32d-2d5ef741adecmsft-kb4507457-3848287d-d32e-4e7b-b6a1-798ba1329599msft-kb4507457-d8ac2164-d4d1-442d-adfa-0b5a886bd8c0
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.