ISA SP2 closes few security holes: buffer overflow during redirect from denied resource, basic credentials may be sent over an External HTTP connection when SSL is required for published server, FTP bounce attack, handles leak in message screener, etc.
It's possible to cause infinite reply loops with spoofed UDP packets with bith source and destination ports 1745 between 2 servers on from server to itself.