PT-2006-7180 · Microsoft · Internet Information Services

Brett Moore

·

Publicado

2006-12-15

·

Atualizado

2020-12-08

·

CVE-2006-6578

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 5.1
Description The issue allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments. This can be demonstrated using win.com when it is in a web directory with certain permissions. The IUSR Machine account can execute non-EXE files such as .COM files.
Recommendations For Microsoft Internet Information Services (IIS) version 5.1, consider restricting the execution of non-EXE files, such as .COM files, by the IUSR Machine account to minimize the risk of exploitation. As a temporary workaround, consider disabling the execution of .COM files in web directories until a patch is available. Restrict access to sensitive web directories to prevent attackers from executing arbitrary commands.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6578

Produtos afetados

Internet Information Services