PT-2012-4087 · Microsoft · Internet Information Services

Justin Royce

·

Published

2012-11-14

·

Updated

2021-02-05

·

CVE-2012-2531

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 7.5
Description The issue concerns weak permissions for the Operational log, allowing local users to discover credentials by reading this file.
Recommendations For Microsoft Internet Information Services (IIS) version 7.5, consider restricting access to the Operational log to prevent local users from reading the file and discovering credentials.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2531

Affected Products

Internet Information Services