Remote Attack Vulnerability in Microsoft Forefront Unified Access Gateway 2010
CVE-2018-12571
9.8CRITICAL
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 5 July 2018
What is CVE-2018-12571?
The vulnerability in Microsoft Forefront Unified Access Gateway 2010 permits remote attackers to send specially crafted URLs through the orig_url parameter. This can trigger arbitrary outbound DNS queries, leading to potential traffic amplification or Server-Side Request Forgery (SSRF). Attackers may exploit this flaw to manipulate DNS requests, resulting in unintended network exposure and compromising system integrity.