An update is available for ISA 2006 with SP1 or less users who uses Radius OTP to authenticate backend web servers. The vulnerability allows an attacker to assume an admin without keying in the correct password (authentication bypass).
Please update your issue of ISA immediately to avoid any possible attacks.
Source MS Article snippet of the update:
Source article: http://www.microsoft.com/technet/security/bulletin/MS09-031.mspx
No comments:
Post a Comment