ISA Security Bulletin

  • From: "Bryan Andrews" <bandrews@xxxxxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 25 Jun 2002 23:16:51 -0400

Hey Guys,

After reading this thoroughly I am a little confused as to the need to patch.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-027.asp

Is this needed only if you are running proxy clients? Or are webservers somehow 
vulnerable as well... 

It seems like anyone who has admin access that views a webpage would 'enable' 
this vulnerability in the users security context.

I did not see any conversations here about it... 

Did most people patch?

Thanks!





Other related posts: