Overview
Symantec Endpoint Protection (SEP) Network Threat Protection module running on a Microsoft Internet Information Services (IIS) webserver contains a denial of service vulnerability when probed by an audit tool.
Description
Symantec Security Advisory SYM12-007 states: Overview |
Impact
An unauthenticated attacker can cause the Microsoft IIS webserver to become unresponsive leading to a denial of service condition. |
Solution
Update |
Restart server or IIS service |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Temporal | 3.2 | E:U/RL:OF/RC:C |
Environmental | 1 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Greg Johnson of Clear Skies Security for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-1821 |
Date Public: | 2012-05-22 |
Date First Published: | 2012-06-05 |
Date Last Updated: | 2012-06-05 12:16 UTC |
Document Revision: | 15 |