PT-2007-4197 · Microsoft · Internet Information Services
Kingcope
·
Publicado
2007-05-30
·
Atualizado
2017-07-29
·
CVE-2007-2897
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) version 6.0
Description
The issue allows remote attackers to cause a denial of service, potentially obtain sensitive information, and possibly execute arbitrary code with physical access. This is achieved by sending requests for a URI containing a '/' immediately before and after the name of a DOS device, effectively bypassing the blacklist for DOS device requests.
Recommendations
For Microsoft Internet Information Services (IIS) version 6.0, consider restricting access to the server to minimize the risk of exploitation, and apply configuration changes to prevent requests for URIs containing DOS device names. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Information Services