PT-2018-11259 · Microsoft · Forefront Unified Access Gateway (Uag) 2010

CVE-2018-12571

·

Published

2018-07-05

·

Updated

2018-09-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Forefront Unified Access Gateway 2010
Description The issue allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig url parameter in the 'uniquesig0/InternalSite/InitParams.aspx' endpoint, possibly causing traffic amplification and/or SSRF outcome.
Recommendations For Microsoft Forefront Unified Access Gateway 2010, consider restricting access to the 'uniquesig0/InternalSite/InitParams.aspx' endpoint to minimize the risk of exploitation. Avoid using the orig url parameter with untrusted input until the issue is resolved.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12571

Affected Products

Forefront Unified Access Gateway (Uag) 2010