← Vulnerability feed

Vulnerability record · CVE-2018-12571 · published 5 July 2018

CVE-2018-12571: Microsoft forefront unified access gateway server-side request forgery (ssrf) vulnerability

Microsoft · Forefront Unified Access Gateway

uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.

9.8 CVSS 3.0 Critical EPSS 30% · top 1.8% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.0 base score, v2 7.5
30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12571 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2011-1969Microsoft forefront unified access gateway code injection vulnerabilityMicrosoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Jav…EPSS 17%5.8CVE-2012-0146Microsoft forefront unified access gateway improper input validation vulnerabilityOpen redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users t…EPSS 11%5.8CVE-2010-2732Microsoft forefront unified access gateway improper input validation vulnerabilityOpen redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allo…EPSS 13%5.0CVE-2012-0147Microsoft forefront unified access gateway vulnerabilityMicrosoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote atta…EPSS 36%5.0CVE-2011-2012Microsoft forefront unified access gateway improper input validation vulnerabilityMicrosoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remo…EPSS 17%4.3CVE-2011-1895Microsoft forefront unified access gateway code injection vulnerabilityCRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to in…EPSS 11%4.3CVE-2011-1896Microsoft forefront unified access gateway cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote att…EPSS 8.3%4.3CVE-2011-1897Microsoft forefront unified access gateway cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote att…EPSS 8.4%

Source: NIST National Vulnerability Database (record CVE-2018-12571), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.