Vulnerability Details CVE-2012-2532
Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Command Injection Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.196
EPSS Ranking 95.2%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2012-2532
-
cpe:2.3:a:microsoft:ftp_service:7.0
-
cpe:2.3:a:microsoft:ftp_service:7.5
-
cpe:2.3:o:microsoft:windows_7:-
-
cpe:2.3:o:microsoft:windows_server_2008:-
-
cpe:2.3:o:microsoft:windows_server_2008:r2
-
cpe:2.3:o:microsoft:windows_vista:-