CVE-2017-0159 is a security feature bypass vulnerability affecting Windows 10 1607, Windows Server 2012 R2, and Windows 2016, where ADFS incorrectly processes Extranet requests as Intranet requests. This vulnerability has a low CVSS score of 3.7, indicating a low attack complexity and potential impact limited to integrity. While there is no known active exploitation, public exploit code, or KEV entry, it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.