Executive Summary

Title Symantec Endpoint Protection network threat protection module Microsoft IIS denial of service vulnerability
Name VU#149070 First vendor Publication 2012-06-05
Vendor VU-CERT Last vendor Modification 2012-06-05
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores


Vulnerability Note VU#149070

Symantec Endpoint Protection network threat protection module Microsoft IIS denial of service vulnerability

Original Release date: 05 Jun 2012 | Last revised: 05 Jun 2012


Symantec Endpoint Protection (SEP) Network Threat Protection module running on a Microsoft Internet Information Services (IIS) webserver contains a denial of service vulnerability when probed by an audit tool.


Symantec Security Advisory SYM12-007 states:

    Versions of Symantec Endpoint Protection Manager 11.0 running the Network Threat Protection module on Windows Server 2003 are susceptible to a Denial of Service(DoS). Successful exploitation could potentially result in the system hosting Symantec Endpoint Protection Manager becoming unresponsive to IIS-based web server requests until restarted.

    Symantec was notified of a Denial of Service(DoS) within the Symantec Endpoint Protection Manager 11 RU6 and related maintenance packs.

    A successful exploitation is possible when using audit tools to aggressively scan the targeted Symantec Endpoint Protection Manager host. After a period of heavy scanning the Network Threat Protection module responds to the perceived threat by blocking all subsequent traffic to the server. This can lead the server to stop serving pages and in some instances can cause excessive resource use which can lead to a hang or crash of the server.

    This issue does not impact the security of the Symantec Endpoint Manager, only the availability of the web server components.

It has been reported that this vulnerability affects Microsoft Internet Information Services (IIS) 6.0, however newer versions could be affected.


An unauthenticated attacker can cause the Microsoft IIS webserver to become unresponsive leading to a denial of service condition.



The vendor has stated that this vulnerability has been addressed in SEP 11.0.7000 RU7 MP2. Users are advised to upgrade to release SEP 11.0.7000 RU7 MP2 or later. The vendor states that updates will be available through customers’ normal support/download locations.

Restart server or IIS service

The vendor has stated that manually restarting the server and/or IIS service will remedy the situation.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
SymantecAffected12 May 201122 May 2012
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)



  • http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120522_00


Thanks to Greg Johnson of Clear Skies Security for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

  • CVE IDs:CVE-2012-1821
  • Date Public:22 May 2012
  • Date First Published:05 Jun 2012
  • Date Last Updated:05 Jun 2012
  • Document Revision:15


If you have feedback, comments, or additional information about this vulnerability, please send us email.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Original Source

Url : http://www.kb.cert.org/vuls/id/149070

CPE : Common Platform Enumeration

Application 7

Nessus® Vulnerability Scanner

Date Description
2012-06-05 Name : The endpoint management application installed on the remote Windows host has ...
File : symantec_endpoint_prot_mgr_11_ru7_mp2.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
Date Informations
2014-02-17 12:07:32
  • Multiple Updates