CVE-2012-2531
Low severity, CVSS 2.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability."
Published 2012-11-14. Last modified 2026-06-16.