Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
BID:49980
Info
Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
| Bugtraq ID: | 49980 |
| Class: | Design Error |
| CVE: |
CVE-2011-2012 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2011 12:00AM |
| Updated: | Apr 19 2013 02:40AM |
| Credit: | Microsoft |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
Microsoft Forefront Unified Access Gateway is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to crash the web server of the affected application, denying service to legitimate users.
Microsoft Forefront Unified Access Gateway is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to crash the web server of the affected application, denying service to legitimate users.
Exploit / POC
Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS11-079 (Microsoft)