HTTP: Microsoft ISA Server 2006 Authentication Bypass

This signature detects attempts to bypass security protections provided by Microsoft Internet Security and Acceleration (ISA) Server 2006, when using Radius One Time Password (OTP) authentication and authentication delegation with Kerberos Constrained Delegation. Using a crafted request, attackers can bypass authentication allowing for privilege escalation. A successful attack can allow an attacker access to otherwise protected files.

Extended Description

Microsoft ISA Server is prone to an authentication-bypass vulnerability. An attacker with knowledge of a valid account name can exploit this issue to bypass authentication and gain access to arbitrary resources within the context of the selected account.

Affected Products

Microsoft isa_server_2006

Short Name
HTTP:ISA-AUTH-BYPASS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
2006 Authentication Bypass CVE-2009-1135 ISA Microsoft Server
Release Date
07/14/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.0

Found a potential security threat?