First published: Wed Apr 15 2009(Updated: )
The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Security And Acceleration Server | =2006-supportability | |
Microsoft Internet Security And Acceleration Server | =2004-sp3 | |
Microsoft Forefront Threat Management Gateway | ||
Microsoft Internet Security And Acceleration Server | =2006-sp1 | |
Microsoft Internet Security And Acceleration Server | =2004-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.