PT-2006-7180 · Microsoft · Internet Information Services
Brett Moore
·
Published
2006-12-15
·
Updated
2020-12-08
·
CVE-2006-6578
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) version 5.1
Description
The issue allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments. This can be demonstrated using win.com when it is in a web directory with certain permissions. The IUSR Machine account can execute non-EXE files such as .COM files.
Recommendations
For Microsoft Internet Information Services (IIS) version 5.1, consider restricting the execution of non-EXE files, such as .COM files, by the IUSR Machine account to minimize the risk of exploitation. As a temporary workaround, consider disabling the execution of .COM files in web directories until a patch is available. Restrict access to sensitive web directories to prevent attackers from executing arbitrary commands.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Information Services