PT-2012-1216 · Microsoft · Internet Information Services+1

Publicado

2012-11-13

·

Atualizado

2021-02-05

·

CVE-2012-2532

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft FTP Service versions 7.0 through 7.5 for Internet Information Services (IIS)
Description The issue is related to the processing of unspecified commands before TLS is enabled for a session, allowing remote attackers to obtain sensitive information by reading the replies to these commands. It is also described as an error in data exchange via the FTP protocol, which can be exploited by a remote attacker to gain unauthorized access to protected information using specially crafted FTP commands.
Recommendations For Microsoft FTP Service versions 7.0 through 7.5, consider disabling the FTP service until a patch is available to prevent exploitation. Restrict access to the FTP module to minimize the risk of unauthorized access to sensitive information.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02390
CVE-2012-2532

Produtos afetados

Internet Information Services
Ftp Service