IIS May Allow Remote Command Execution

Three vulnerabilities were recently discovered in Microsoft’s Internet Information Server (IIS) 4.0 and Microsoft’s Internet Information Services (IIS) 5.0 that can lead to a Denial of Service (DoS), remote code execution, and information disclosure.

Ken Pfeil

May 14, 2001

2 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedMay 14, 2001, by Microsoft.

VERSIONSAFFECTED

  • Microsoft Internet Information Server 4.0

  • Microsoft Internet Information Services 5.0

 

DESCRIPTION
Threevulnerabilities were recently discovered in Microsoft’s Internet InformationServer (IIS) 4.0 and Microsoft’s Internet Information Services (IIS) 5.0 thatcan lead to a Denial of Service (DoS), remote code execution, and informationdisclosure. The DoS vulnerability is in the function that processes wild-cardservice requests for the FTP service. The remote code execution vulnerabilitylets a potential attacker run scripts on the server by using the securitycontext of IUSR_machinename, which by default appears in the Everyone group. Theinformation disclosure vulnerability lets an attacker find guest accounts thatFTP inadvertently exposed. You can find more detailed information about thesevulnerabilities on Microsoft’s Website.

 

 

VENDORRESPONSE

Thevendor, Microsoft, has acknowledgedthese vulnerabilities and recommends that users immediately apply the patchcontained in SecurityBulletin MS01-026

 

CREDIT
Discoveredby Nsfocus, Lukasz Luzar, Aiden O’Rawe, and Kevin Kotas.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like