IIS May Allow Remote Command Execution
Three vulnerabilities were recently discovered in Microsoft’s Internet Information Server (IIS) 4.0 and Microsoft’s Internet Information Services (IIS) 5.0 that can lead to a Denial of Service (DoS), remote code execution, and information disclosure.
May 14, 2001
ReportedMay 14, 2001, by Microsoft.
VERSIONSAFFECTED
Microsoft Internet Information Server 4.0
Microsoft Internet Information Services 5.0
DESCRIPTION
Threevulnerabilities were recently discovered in Microsoft’s Internet InformationServer (IIS) 4.0 and Microsoft’s Internet Information Services (IIS) 5.0 thatcan lead to a Denial of Service (DoS), remote code execution, and informationdisclosure. The DoS vulnerability is in the function that processes wild-cardservice requests for the FTP service. The remote code execution vulnerabilitylets a potential attacker run scripts on the server by using the securitycontext of IUSR_machinename, which by default appears in the Everyone group. Theinformation disclosure vulnerability lets an attacker find guest accounts thatFTP inadvertently exposed. You can find more detailed information about thesevulnerabilities on Microsoft’s Website.
VENDORRESPONSE
Thevendor, Microsoft, has acknowledgedthese vulnerabilities and recommends that users immediately apply the patchcontained in SecurityBulletin MS01-026.
CREDIT
Discoveredby Nsfocus, Lukasz Luzar, Aiden O’Rawe, and Kevin Kotas.
About the Author
You May Also Like