PT-2007-4197 · Microsoft · Internet Information Services

Kingcope

·

Publicado

2007-05-30

·

Atualizado

2017-07-29

·

CVE-2007-2897

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 6.0
Description The issue allows remote attackers to cause a denial of service, potentially obtain sensitive information, and possibly execute arbitrary code with physical access. This is achieved by sending requests for a URI containing a '/' immediately before and after the name of a DOS device, effectively bypassing the blacklist for DOS device requests.
Recommendations For Microsoft Internet Information Services (IIS) version 6.0, consider restricting access to the server to minimize the risk of exploitation, and apply configuration changes to prevent requests for URIs containing DOS device names. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2897

Produtos afetados

Internet Information Services