cve/2019/CVE-2019-1006.md

139 lines
17 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-1006](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1006)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%202.0&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.0&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20Version%201809%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%2010%20Version%201809%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%20Server%202019%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.7.2%20on%20Windows%20Server%202019&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201809%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201809%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201903%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%2010%20Version%201903%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%202019%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%202019&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5%20AND%204.8%20on%20Windows%20Server%2C%20version%201903%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%203.5.1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.5.2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.6%2F4.6.1%2F4.6.2%2F4.7%2F4.7.1%2F4.7.2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.6%2F4.6.1%2F4.6.2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.6&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201607%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201607%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201703%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201703%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201709%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201709%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201803%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%2010%20Version%201803%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%207%20for%2032-bit%20Systems%20Service%20Pack%201&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%207%20for%20x64-based%20Systems%20Service%20Pack%201&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%208.1%20for%2032-bit%20systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%208.1%20for%20x64-based%20systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20RT%208.1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012%20R2%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012%20R2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202012&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202016%20%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%202016&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20.NET%20Framework%204.8%20on%20Windows%20Server%2C%20version%201803%20%20(Server%20Core%20Installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20SharePoint%20Enterprise%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20SharePoint%20Foundation&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft%20SharePoint%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Microsoft.IdentityModel&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201903%20for%2032-bit%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201903%20for%20ARM64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201903%20for%20x64-based%20Systems&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%2C%20version%201903%20(Server%20Core%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows&color=blue)
2025-09-29 21:09:30 +02:00
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201607%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201607%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201703%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201703%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201709%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201709%20for%20ARM64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201709%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201803%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201803%20for%20ARM64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201803%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201809%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201809%20for%20ARM64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20Version%201809%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=1903%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20R2%20for%20Itanium-Based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20for%2032-bit%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20for%2032-bit%20Systems%20Service%20Pack%202%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20for%20Itanium-Based%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20for%20x64-based%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2008%20for%20x64-based%20Systems%20Service%20Pack%202%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2010%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2012%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2012%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2012%20R2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2012%20R2%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2013%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2016%20%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2016%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2019%20%20(Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=2019%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=7%20for%2032-bit%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=7%20for%20x64-based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=7.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=8.1%20for%2032-bit%20systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=8.1%20for%20x64-based%20systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=RT%208.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Service%20Pack%202%20on%20Windows%20Server%202008%20for%2032-bit%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Service%20Pack%202%20on%20Windows%20Server%202008%20for%20Itanium-Based%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Service%20Pack%202%20on%20Windows%20Server%202008%20for%20x64-based%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201607%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201607%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201703%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201703%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201709%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201709%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201803%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20Version%201803%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20for%2032-bit%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%2010%20for%20x64-based%20Systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%207%20for%2032-bit%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%207%20for%20x64-based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%208.1%20for%2032-bit%20systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%208.1%20for%20x64-based%20systems%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20RT%208.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202008%20R2%20for%20Itanium-Based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202008%20R2%20for%20x64-based%20Systems%20Service%20Pack%201%20(Server%20Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202008%20for%2032-bit%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202008%20for%20x64-based%20Systems%20Service%20Pack%202%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202012%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202012%20(Server%20Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202012%20R2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202012%20R2%20(Server%20Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202016%20%20(Server%20Core%20installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%202016%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=Windows%20Server%2C%20version%201803%20%20(Server%20Core%20Installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=version%201803%20%20(Core%20Installation)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Elevation%20of%20Privilege&color=brightgreen)
2024-05-26 14:27:05 +02:00
### Description
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/521526/CVE-2019-1006