QID 376656
Date Published: 2022-06-13
QID 376656: Microsoft Identity Manager Cross-Site Scripting (XSS) Elevation of Privilege Vulnerability
Microsoft Identity Manager (MIM) 2016 helps you manage the users, credentials, policies, and access within your organization.
Microsoft Identity Manager is prone to a remote privilege-escalation vulnerability because it fails to properly sanitize user-supplied input: CVE-2018-0908
Affected Versions:
Microsoft Identity Manager 2016 SP1
QID Detection Logic(Authenticated)
It checks for vulnerable version of Microsoft Identity Manager 2016 SP1
An attacker may exploit this issue to gain elevated privileges. Successful exploits may aid in further attacks.
Solution
Customers are advised to follow KB4050936 for instructions pertaining to the remediation of these vulnerabilities.
Vendor References
CVEs related to QID 376656
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB4050936 |
|