CVE-2009-0077
5.0
CVSS v2.0 Base Score
88.70%
HIGH RiskEPSS (100th percentile)
NVD-CWE-Other
The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."
Published: 4/15/2009
Modified: 4/23/2026
Vulnerability Summary
CVSS v2 Score
5
AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Score (Exploitation Probability)
88.70%HIGH Exploitation Risk
100th percentile
This vulnerability has a 88.70% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.
CWE Classification
NVD-CWE-Other