vulnerability

Microsoft Windows: CVE-2019-1126: ADFS Security Feature Bypass Vulnerability

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jul 9, 2019
Added
Jul 9, 2019
Modified
Sep 5, 2025

Description

A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Directory.This security update corrects how ADFS handles external authentication requests., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0975.

Solutions

microsoft-windows-windows_server_2012_r2-kb4507457microsoft-windows-windows_server_2016-1607-kb4507460microsoft-windows-windows_server_2019-1809-kb4507469msft-kb4507453-8cedcb21-0200-433d-b32d-2d5ef741adecmsft-kb4507457-3848287d-d32e-4e7b-b6a1-798ba1329599msft-kb4507457-d8ac2164-d4d1-442d-adfa-0b5a886bd8c0
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.