CVE-2025-21193
published 2025-01-14CVE-2025-21193: Active Directory Federation Server Spoofing Vulnerability
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.74%
50.7th percentile
Active Directory Federation Server Spoofing Vulnerability
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2016 | < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_server_2019 | < 10.0.17763.6775 | 10.0.17763.6775 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.6775 | 10.0.17763.6775 |
| microsoft | windows_server_2022 | < 10.0.20348.3091 | 10.0.20348.3091 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3091 | 10.0.20348.3091 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1369 | 10.0.25398.1369 |
| microsoft | windows_server_2025 | < 10.0.26100.2894 | 10.0.26100.2894 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.2894 | 10.0.26100.2894 |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Active Directory Federation Server Spoofing Vulnerability
vendor_msrc·2025-01-14·CVSS 6.5
CVE-2025-21193 [MEDIUM] CWE-352 Active Directory Federation Server Spoofing Vulnerability
Active Directory Federation Server Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
In a web-based attack scenario, an attacker could host a website or server that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.
Active Directory Federation Services: Active Directory Federation Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Dis
GHSA
GHSA-4wgp-9wjx-2m53: Active Directory Federation Server Spoofing Vulnerability
ghsa_unreviewed·2025-01-14
CVE-2025-21193 [MEDIUM] CWE-352 GHSA-4wgp-9wjx-2m53: Active Directory Federation Server Spoofing Vulnerability
Active Directory Federation Server Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
2025-01-14
Published