PT-2007-4197 · Microsoft · Internet Information Services

Kingcope

·

Published

2007-05-30

·

Updated

2017-07-29

·

CVE-2007-2897

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 6.0
Description The issue allows remote attackers to cause a denial of service, potentially obtain sensitive information, and possibly execute arbitrary code with physical access. This is achieved by sending requests for a URI containing a '/' immediately before and after the name of a DOS device, effectively bypassing the blacklist for DOS device requests.
Recommendations For Microsoft Internet Information Services (IIS) version 6.0, consider restricting access to the server to minimize the risk of exploitation, and apply configuration changes to prevent requests for URIs containing DOS device names. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2897

Affected Products

Internet Information Services