PT-2009-6566 · Microsoft · Internet Information Services

Publicado

2009-12-29

·

Atualizado

2017-08-17

·

CVE-2009-4445

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) (affected versions not specified)
Description The issue allows remote attackers to create empty files with arbitrary extensions when used with unspecified third-party upload applications. This is achieved by using a filename containing an initial extension followed by a : (colon) and a safe extension. For example, uploading a .asp:.jpg file results in the creation of an empty .asp file. This is related to support for the NTFS Alternate Data Streams (ADS) filename syntax.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4445

Produtos afetados

Internet Information Services