PT-2002-2166 · Microsoft · Iis

Published

2002-11-12

·

Updated

2020-11-23

·

CVE-2002-1182

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: IIS versions 5.0 through 5.1
Description: The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending malformed WebDAV requests. These requests cause a large amount of memory to be assigned.
Recommendations: For IIS versions 5.0 through 5.1, consider restricting access to WebDAV requests until a fix is available. As a temporary workaround, limiting the amount of memory that can be assigned by WebDAV requests may help mitigate the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1182

Affected Products

Iis