FTP Command Injection Vulnerability in Microsoft IIS
CVE-2012-2532

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 November 2012

Summary

The Microsoft FTP Service versions 7.0 and 7.5 for Internet Information Services (IIS) contains a vulnerability that allows unauthorized command processing before establishing a secure TLS session. This flaw can be exploited by remote attackers to retrieve sensitive information through the responses generated from the processed commands. As a result, it poses a significant risk to system integrity and data confidentiality.

References

EPSS Score

19% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.