Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Internet Information Services (IIS).
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2017-7269CRITICAL | Microsoft Windows Server Buffer Overflow VulnerabilityBuffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016. | CVSS9.8v3.1 | EPSS99.8% | PoCs22 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
Microsoft Internet Information Services (IIS) Uncontrolled Resource ConsumptionStack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability." CWE-400Sep 4, 2009 | CVSS5.0v2.0 | EPSS82.3% | PoCs3 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability." CWE-120Aug 31, 2009 | CVSS9.0v2.0 | EPSS90.9% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Integer Overflow or WraparoundInteger overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability." CWE-190Oct 15, 2008 | CVSS9.0v2.0 | EPSS46.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft IIS SERVER_NAME Variable Bypass VulnerabilityMicrosoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost. Aug 23, 2005 | CVSS5.0v2.0 | EPSS39.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. Sep 18, 2001 | CVSS7.5v2.0 | EPSS90.8% | PoCs10 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft IIS 4.0 and 5.0 Folder Traversal VulnerabilityIIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. Jan 22, 2001 | CVSS7.5v2.0 | EPSS70.6% | PoCs9 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized ActorIIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. Feb 4, 2000 | CVSS5.0v2.0 | EPSS26.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |