PT-2002-2417 · Microsoft · Internet Information Server
Published
2002-12-31
·
Updated
2018-10-30
·
CVE-2002-1694
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Server (IIS) version 4.0
Description
The issue allows remote attackers to modify log file contents while the server is running, due to the log files being opened with FILE SHARE READ and FILE SHARE WRITE permissions.
Recommendations
For Microsoft Internet Information Server (IIS) version 4.0, consider restricting access to the log files to prevent modification by remote attackers. As a temporary workaround, restrict write access to the log files until a more permanent solution is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Information Server