PT-2012-4087 · Microsoft · Internet Information Services
Justin Royce
·
Published
2012-11-14
·
Updated
2021-02-05
·
CVE-2012-2531
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) version 7.5
Description
The issue concerns weak permissions for the Operational log, allowing local users to discover credentials by reading this file.
Recommendations
For Microsoft Internet Information Services (IIS) version 7.5, consider restricting access to the Operational log to prevent local users from reading the file and discovering credentials.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Information Services