Home / bulletins MS09-070 - Important: Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726) - Version:1.0
Posted on 08 December 2009
There is an newer version: MS09-070 - Version: 1.1
ImportantSeverity Rating: Important - Revision Note: V1.0 (December 8, 2009): Bulletin published.Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The more severe of these vulnerabilities could allow remote code execution if an attacker sent a specially crafted HTTP request to an ADFS-enabled Web server. An attacker would need to be an authenticated user in order to exploit either of these vulnerabilities.
Other versions
- MS09-070 - Version: 1.0
- MS09-070 - Version: 1.1