Security Portal

Intrusion Prevention Service

 
Signature Version: 4.788

 



WEB Microsoft Forefront Unified Access Gateway NULL Session Cookie Denial of Service (CVE-2011-2012)
 
Threat Level: High
Release Date: 2011/12/26
 
Category: Web Attacks
Signature ID: 1055155
Included In: Full
Affected OS: Windows
 
Description: A denial of service vulnerability exists in Microsoft Forefront Unified Access Gateway. The vulnerability is due to improper validation of session cookies with a NULL value.
 
Impact: Remote code execution
Recommendation: Update vendor's patch.
 
False Positive: None
False Negative: Medium. Due to the cookie name variation.
 
Additional Information (Links open in new window):
Reference(s): CVE-2011-2012; MS11-079
 

Search the Threat Database
Enter Rule ID or Name