Microsoft
Microsoft Internet Information Services: vulnerabilidades y CVE
Microsoft Internet Information Services tiene 94 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE94
Últimos 12 meses0
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-7269 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 mar 2017 | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-7269 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 mar 2017 | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long… |
| CVE-2014-4078 | Media (5.1) | 20% | — | 11 nov 2014 | The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes… |
| CVE-2011-5279 | Media (5) | 19% | — | 23 abr 2014 | CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment… |
| CVE-2012-2531 | Baja (2.1) | 0.94% | — | 14 nov 2012 | Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability." |
| CVE-2010-3972 | Alta (10) | 95% | — | 23 dic 2010 | Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to… |
| CVE-2010-2731 | Media (6.8) | 31% | — | 15 sept 2010 | Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and… |
| CVE-2010-2730 | Alta (9.3) | 33% | — | 15 sept 2010 | Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow… |
| CVE-2010-1899 | Media (4.3) | 57% | — | 15 sept 2010 | Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted… |
| CVE-2009-4445 | Media (6) | 13% | — | 29 dic 2009 | Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing… |
| CVE-2009-4444 | Media (6) | 64% | — | 29 dic 2009 | Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension… |
| CVE-2009-2521 | Media (5) | 82% | — | 4 sept 2009 | Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R… |
| CVE-2009-1122 | Alta (7.5) | 98% | — | 10 jun 2009 | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via… |
| CVE-2009-1535 | Alta (7.5) | 98% | — | 10 jun 2009 | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af… |
| CVE-2003-1567 | Alta (7.5) | 25% | — | 15 ene 2009 | The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and… |
| CVE-2003-1566 | Media (5) | 28% | — | 15 ene 2009 | Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection. |
| CVE-2008-1446 | Alta (9) | 46% | — | 15 oct 2008 | Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008… |
| CVE-2008-4301 | Alta (10) | 17% | — | 29 sept 2008 | A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be… |
| CVE-2008-4300 | Media (5) | 14% | — | 29 sept 2008 | A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject… |
| CVE-2008-0074 | Alta (7.2) | 5.4% | — | 12 feb 2008 | Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or… |
| CVE-2007-2815 | Alta (10) | 73% | — | 22 may 2007 | The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic… |
| CVE-2006-6579 | Media (4.4) | 1.4% | — | 15 dic 2006 | Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an… |
| CVE-2006-6578 | Alta (7.5) | 7.0% | — | 15 dic 2006 | Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that… |
| CVE-2006-0026 | Media (6.5) | 89% | — | 11 jul 2006 | Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). |
| CVE-2005-4360 | Alta (7.8) | 87% | — | 20 dic 2005 | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0"… |
| CVE-2005-2678 | Media (5) | 42% | — | 23 ago 2005 | Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the… |
| CVE-2005-2089 | Media (4.3) | 31% | — | 5 jul 2005 | Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a… |
| CVE-2003-0718 | Media (5) | 88% | — | 3 nov 2004 | The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML… |
| CVE-2003-0225 | Media (5) | 38% | — | 9 jun 2003 | The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a… |
| CVE-2003-0224 | Alta (10) | 18% | — | 9 jun 2003 | Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server… |
| CVE-2003-0226 | Media (5) | 43% | — | 9 jun 2003 | Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.