PT-2014-5698 · Microsoft · Internet Information Services
Published
2014-11-11
·
Updated
2025-07-21
·
CVE-2014-4078
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) versions 8.0 through 8.5
Description
The IP Security feature in Microsoft Internet Information Services (IIS) does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list. This makes it easier for remote attackers to bypass an intended rule set via an HTTP request.
Recommendations
For IIS versions 8.0 through 8.5, consider reconfiguring the "IP Address and Domain Restrictions" list to avoid using wildcard rules until a proper fix is available. As a temporary workaround, restrict access to sensitive areas of the web server to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Information Services