Skip to main content

CVE-2009-0077

5.0
CVSS v2.0 Base Score
88.70%
HIGH RiskEPSS (100th percentile)
NVD-CWE-Other

The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."

Published: 4/15/2009
Modified: 4/23/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

5

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Score (Exploitation Probability)

88.70%HIGH Exploitation Risk
100th percentile

This vulnerability has a 88.70% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-Other