CVE-2012-2532

Description

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka FTP Command Injection Vulnerability.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
19.645

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 7 (KB2716513) x86 based systemsWindows
Security Update for Windows 7 (KB2716513) x86 based systems for SP1Windows
Security Update for Windows 7 for x64-based Systems (KB2716513)Windows
Security Update for Windows 7 for x64-based Systems (KB2716513) for SP1Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2716513)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2716513) for SP1Windows
Security Update for Windows 7 (KB2719033) x86 based systemsWindows
Security Update for Windows 7 (KB2719033) x86 based systems for SP1Windows
Security Update for Windows 7 for x64-based Systems (KB2719033)Windows
Security Update for Windows 7 for x64-based Systems (KB2719033) for SP1Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2719033)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2719033) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12659Security Update for Windows 7 (KB2716513)
PATCH-12660Security Update for Windows 7 (KB2716513)
PATCH-12665Security Update for Windows 7 for x64-based Systems (KB2716513)
PATCH-12666Security Update for Windows 7 for x64-based Systems (KB2716513)
PATCH-12667Security Update for Windows Server 2008 R2 x64 Edition (KB2716513)
PATCH-12668Security Update for Windows Server 2008 R2 x64 Edition (KB2716513)
PATCH-12669Security Update for Windows 7 (KB2719033)
PATCH-12670Security Update for Windows 7 (KB2719033)
PATCH-12671Security Update for Windows 7 for x64-based Systems (KB2719033)
PATCH-12672Security Update for Windows 7 for x64-based Systems (KB2719033)
PATCH-12673Security Update for Windows Server 2008 R2 x64 Edition (KB2719033)
PATCH-12674Security Update for Windows Server 2008 R2 x64 Edition (KB2719033)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234