CVE-2017-8613

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
29/06/2017
Last modified:
20/04/2025

Description

Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:azure_active_directory_connect:*:*:*:*:*:*:*:* 1.1.524.0 (including)