CVE-2020-1055
CVE-2020-1055: 1 tracked advisory record across MS Server. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
MS Server
1 advisory- Advisory severityMedium5.5
Medium [CVE-2020-1055] Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability
CVE-2020-1055Source published Source updated
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).
- Affected products in this advisory
- Windows Server 2019 (Server Core installation)
- Windows Server, version 1903 (Server Core installation)
- Windows Server, version 1909 (Server Core installation)
- Source-reported affected versions
- Windows 10 Version 1809 10.0.17763.0 before publication
- Windows 10 Version 1809 10.0.0 before publication
- Windows 10 Version 1903 for 32-bit Systems 10.0.0 before publication
- Windows 10 Version 1903 for ARM64-based Systems 10.0.0 before publication
6 more entries in the full advisory.
- Source-reported fixed versions
- publication
- Mitigation guidance
- This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs.
Android app · Google Play
Monitor future MS Server CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.