PT-2005-5046 · Microsoft · Ntdll.Dll+2
Adi Sharabani
+2
·
Published
2005-12-20
·
Updated
2021-11-08
·
CVE-2005-4360
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2
Description
The issue concerns the URL parser in Microsoft Internet Information Services (IIS) 5.1, allowing remote attackers to execute arbitrary code. This is achieved through multiple requests to ".dll" followed by specific arguments, such as
~0 through ~9, which causes ntdll.dll to produce a return value that IIS does not handle correctly. An example of such a request is "/ vti bin/.dll/*/~0". Initially, it was believed that the consequence of this issue would only be a denial of service, resulting in an application crash and reboot.Recommendations
For Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2, consider restricting access to the URL parser or applying specific configuration changes to handle the return value from ntdll.dll correctly until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
DoS
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Information Services
Windows Xp
Ntdll.Dll