The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka Web Proxy TCP State Limited Denial of Service Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Forefront_threat_management_gateway | Microsoft | - (including) | - (including) |
Internet_security_and_acceleration_server | Microsoft | 2004-sp3 (including) | 2004-sp3 (including) |
Internet_security_and_acceleration_server | Microsoft | 2006-sp1 (including) | 2006-sp1 (including) |
Internet_security_and_acceleration_server | Microsoft | 2006-supportability (including) | 2006-supportability (including) |