Null Session Cookie Crash Vulnerability (CVE 2011-2012)
Publish date: 21 de julio de 2015
Gravedad: Medio
Identificadores de CVE : CVE-2011-2012,MS 11-079
Fecha recomendada: 21 de julio de 2015
Descripción
Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
Revelación de la información
Apply associated Trend Micro DPI Rules.
Soluciones
Trend Micro Deep Security DPI Rule Number: 1004822
Trend Micro Deep Security DPI Rule Name: 1004822 - Null Session Cookie Crash Vulnerability (CVE 2011-2012)
Software y versión afectados
- microsoft forefront_unified_access_gateway 2010