Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Preemptive Protection against Microsoft Forefront UAG ExcelTable Reflected XSS Information Disclosure (MS11-079; CVE-2011-1896)

Subscribe

Check Point Reference: CPAI-2011-472
Date Published:
Preemptive Since:
Severity:
Source: Microsoft Security Bulletin MS11-079
Industry Reference(s): CVE-2011-1896
Protection Provided by: Security Gateway
  • R70
  • R71
  • R75
VPN-1
  • NGX R65
VSX
  • NGX R65
Who is Vulnerable?
Microsoft Forefront Unified Access Gateway 2010
Microsoft Forefront Unified Access Gateway 2010 Service Pack 1
Microsoft Forefront Unified Access Gateway 2010 Update 1
Microsoft Forefront Unified Access Gateway 2010 Update 2
Vulnerability Description
An information disclosure vulnerability has been reported in Microsoft Forefront Unified Access Gateway (UAG) server.
Update/Patch Available
Apply patches from:
MS11-079
Vulnerability Details
The vulnerability is due to a defect in Forefront Unified Access Gateway (UAG) that allows content to be reflected back to the user. A remote attacker may exploit this vulnerability by enticing a target UAG user to click on a link containing a malicious script. Successful exploitation may result in potentially sensitive information being disclosed to an unprivileged user.

Protection Overview
This protection will detect and block attempts to exploit this vulnerability.

No update is required to address this vulnerability.
Users are protected against this vulnerability if the Cross-Site Scripting protection found in the Protection section of CPSA-2005-03 has been applied.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R75 / R71 / R70

How Can I Protect My Network?
1. In the IPS tab, click Protections and find the Cross Site Scripting protection using the Search tool and Edit the protection's settings.
2. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Cross site scripting
Attack Information: WSE0030001 cross site scripting detected in URL