First published: Wed Nov 14 2012(Updated: )
Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 7 | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2531 is considered a moderate severity vulnerability due to its potential to disclose sensitive credentials.
To fix CVE-2012-2531, you should update permissions on the Operational log to restrict unauthorized access.
CVE-2012-2531 affects users of Microsoft Internet Information Services (IIS) 7.5 running on Windows 7 and Windows Server 2008 R2.
Exploiting CVE-2012-2531 can allow local users to read the Operational log and potentially gain access to sensitive credentials.
CVE-2012-2531 is primarily a concern for legacy systems, though proper security practices should always be followed to mitigate risks.