IIS 4.0 and 5.0 May Allow Elevated File Privileges

By using specially craft URL, a user could gain elevated privileges to files on the system

ITPro Today

August 10, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

 

Reported August 9, 2000 by Burt Abreu and Søren Skov of VBExplorer.com

VERSIONS EFFECTED

  • Microsoft Internet Information Server 4.x

Microsoft Internet Information Server 5.x DESCRIPTION

An error in IIS canoncalization could allow a user to gain elevated priveleges to specific files under particular circumstances. By using a specifically crafted URL, permission to access a specfic file would be determined by the permissions applied to a directory in the file's parent chain instead of the file's actual resident directory permissions.

Microsoft's bulletin points out that this problem only affects scripts and file types that are implemented via ISAPI extensions. In addition, the problem only affects IIS when virtual paths mirror actual physical directory paths.

VENDOR RESPONSE

Microsoft issued FAQ #FQ00-057, Support Online article Q269862, as well as patches for IIS 4.x and IIS 5.x.

CREDIT
Discovered by Burt Abreu and Søren Skov of VBExplorer.com

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like