PT-2006-7180 · Microsoft · Internet Information Services

Brett Moore

·

Published

2006-12-15

·

Updated

2020-12-08

·

CVE-2006-6578

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 5.1
Description The issue allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments. This can be demonstrated using win.com when it is in a web directory with certain permissions. The IUSR Machine account can execute non-EXE files such as .COM files.
Recommendations For Microsoft Internet Information Services (IIS) version 5.1, consider restricting the execution of non-EXE files, such as .COM files, by the IUSR Machine account to minimize the risk of exploitation. As a temporary workaround, consider disabling the execution of .COM files in web directories until a patch is available. Restrict access to sensitive web directories to prevent attackers from executing arbitrary commands.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6578

Affected Products

Internet Information Services