Vulnerability record · CVE-2009-0077 · published 15 April 2009
CVE-2009-0077: Microsoft Forefront TMG and ISA Server web listener session state DoS
Microsoft · Forefront Threat Management Gateway
The firewall engine in Microsoft Forefront Threat Management Gateway Medium Business Edition and ISA Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1 fails to properly manage web listener session state. Crafted packets cause stale sessions to accumulate, exhausting resources and denying service to legitimate users. The flaw is remotely reachable over the network without authentication.
Description
The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote denial of service against perimeter security infrastructure, with very high EPSS despite no KEV listing.
What it is
The firewall engine in Microsoft Forefront Threat Management Gateway Medium Business Edition and ISA Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1 fails to properly manage web listener session state. Crafted packets cause stale sessions to accumulate, exhausting resources and denying service to legitimate users. The flaw is remotely reachable over the network without authentication.
Impact
An unauthenticated remote attacker can exhaust the web listener session table, degrading or blocking proxy and firewall traffic for legitimate users. The CVSS vector shows availability impact only, with no confidentiality or integrity loss.
Attack surface
Reached over the network through the web proxy listener (AV:N, Au:N), requiring no authentication and no user interaction. The description attributes the trigger to crafted packets sent to the affected firewall engine.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high at 0.785 (99.6th percentile), indicating elevated predicted exploitation activity. No public exploit code is confirmed by the supplied references.
What to do
- Apply the Microsoft security update for MS09-016 (April 2009) to all affected Forefront TMG MBE and ISA Server 2004/2006 installations.
- Retire or isolate end-of-life ISA Server 2004/2006 and TMG MBE systems that can no longer be patched.
- Restrict network access to web proxy listeners to trusted source ranges where operationally feasible.
- Monitor listener session counts and set alerting thresholds to catch abnormal session accumulation early.
Detection
- Track web listener session table size and stale session counts on the firewall/proxy for abnormal growth.
- Alert on bursts of connection attempts to the proxy listener from single or few source IPs.
- Review proxy and firewall logs for repeated half-open or abandoned TCP sessions tied to the web listener.
- Correlate availability degradation events with spikes in inbound proxy connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0077 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0077), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.