Two vulnerabilities have been reported in Microsoft ISA server which could be exploited to poison cache contents and bypass security restrictions.
Impact
The remote attacker can exploit these vulnerabilities to manipulate cache content and bypass security restrictions.
Microsoft ISA server vulnerability in handling malformed HTTP request may be exploited by remote attacker to manipulate cache contents. A remote attacker may exploit this vulnerability by specially crafted malicious HTTP packets to poison cache contents it could allow manipulation of cache content and access to cache contents which otherwise not accessible to the malicious attacker. The attacker may direct user to unexpected content. An attacker may combine this vulnerability with other cross site scripting vulnerability to gain sensitive information like login credentials.
Microsoft ISA server vulnerability in the process used to validate NetBIOS connections through the NetBIOS all predefined packet filter may be exploited by remote attacker to establish connection to the services on ISA server utilizing NETBIOS protocol.
The information provided herein is on "as is" basis, without warranty of any kind.