Summary

This security update resolves a vulnerability in Active Directory Federation Services (AD FS). The vulnerability could allow information disclosure if a user leaves a browser open after the user logs off from an application and an attacker reopens the application in the browser immediately after the user logs off. 

Introduction

Microsoft has released security bulletin MS15-040. To learn more about this security bulletin:

How to obtain help and support for this security update

Help installing updates:
Support for Microsoft Update

Security solutions for IT professionals:
TechNet Security Troubleshooting and Support

Help protect your Windows-based computer from viruses and malware:
Virus Solution and Security Center

Local support according to your country:
International Support

More Information

Security update deployment information

Reference Table
The following table contains the security update information for this software.

Security update file name

For all supported editions of Windows Server 2012 R2:
Windows8.1-KB3045711-x64.msu

Installation switches

See Microsoft Knowledge Base Article 934307

Restart requirement

For all supported editions of Windows Server 2012 R2:
This update does not require a system restart. However, the AD FS service (adfssrv) will have to be stopped before you install the update and then restarted after the update is complete.

Removal information

To uninstall an update that was installed by WUSA, use the /Uninstall setup switch, or click Control Panel, click System and Security, click Windows Update, and then, under See also, click Installed updates and select from the list of updates.

File information

See the file information section.

Registry key verification

Note A registry key does not exist to validate the presence of this update.


File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.




For all supported x64-based versions of Windows 8.1 and Windows Server 2012 R2

File name

File version

File size

Date

Time

Platform

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

180,224

24-Jul-2014

23:55

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

197,120

25-Jul-2014

00:02

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

173,056

24-Jul-2014

13:37

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

203,776

24-Jul-2014

23:43

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

209,920

24-Jul-2014

23:56

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

194,560

24-Jul-2014

23:59

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

194,048

25-Jul-2014

00:00

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

106,496

24-Jul-2014

23:59

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

104,960

24-Jul-2014

23:52

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

190,464

24-Jul-2014

23:56

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

192,000

24-Jul-2014

23:44

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

196,608

24-Jul-2014

23:49

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

198,656

24-Jul-2014

23:43

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

188,928

24-Jul-2014

23:42

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

179,712

24-Jul-2014

23:59

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

175,104

25-Jul-2014

00:07

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

80,384

25-Jul-2014

00:02

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

86,016

24-Jul-2014

23:56

Not applicable

Microsoft.identityserver.nativeresources.dll.mui

6.1.0.0

86,016

24-Jul-2014

23:56

Not applicable

Microsoft.identityserver.nativeresources.dll

6.1.0.0

149,504

24-Jul-2014

11:52

x64

Microsoft.identityserver.diagnostics.dll

6.3.9600.17720

151,552

05-Mar-2015

07:29

x86

Microsoft.identityserver.proxyservice.exe

6.3.9600.17720

73,216

05-Mar-2015

07:29

x86

Microsoft.identityserver.proxyservice.exe.config

Not applicable

1,067

15-Mar-2014

00:10

Not applicable

Microsoft.identityserver.service.dll

6.3.9600.17720

693,760

05-Mar-2015

07:29

x86

Microsoft.identityserver.webhost.dll

6.3.9600.17720

175,104

05-Mar-2015

07:29

x86

Microsoft.identityserver.web.dll

6.3.9600.17720

814,080

05-Mar-2015

07:29

x86

Microsoft.identityserver.dll

6.3.9600.17720

653,312

05-Mar-2015

07:29

x86


Package Name

Package Hash SHA1

Package Hash SHA2

Windows8.1-KB3045711-x64.msu

6D08BDFA56D95EE595E9ECA9FB1D4E769725133D

4A0E141FF5505E8F43EB37D0BA75431A28B12A78A04DD360F53BD7F67FC06E03


Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

What affected your experience?

Thank you for your feedback!

×