The flaw lets an attacker use the same second factor to bypass multifactor authentication for any account on the same ADFS service. …read more

Source:: DarkReading