Information Disclosure Vulnerability in Microsoft ISA Server
CVE-2007-4991

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
21 September 2007

Summary

The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 is affected by a vulnerability that allows remote attackers to retrieve sensitive information. An attacker can exploit this flaw by sending an empty packet, which may reveal the destination IP address of another user's session. This could potentially lead to further attacks or privacy violations. Organizations using this software should implement necessary security measures to mitigate the risks associated with this vulnerability.

References

EPSS Score

47% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.