Showing 8 vulnerabilities on this page for Internet Information Services (IIS)

Signals CISA KEV Ransomware Nuclei
Microsoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Microsoft Windows Server Buffer Overflow Vulnerability

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

CWE-119CWE-120Mar 27, 20171 related artifact
CVSS9.8v3.1EPSS99.8%PoCs22SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Microsoft Internet Information Services (IIS) Uncontrolled Resource Consumption

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."

CWE-400Sep 4, 2009
CVSS5.0v2.0EPSS82.3%PoCs3SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Microsoft Internet Information Services (IIS) Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."

CWE-120Aug 31, 2009
CVSS9.0v2.0EPSS90.9%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Internet Information Services (IIS) Integer Overflow or Wraparound

Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."

CWE-190Oct 15, 2008
CVSS9.0v2.0EPSS46.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft IIS SERVER_NAME Variable Bypass Vulnerability

Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.

Aug 23, 2005
CVSS5.0v2.0EPSS39.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Internet Information Services (IIS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

Sep 18, 2001
CVSS7.5v2.0EPSS90.8%PoCs10SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft IIS 4.0 and 5.0 Folder Traversal Vulnerability

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

Jan 22, 2001
CVSS7.5v2.0EPSS70.6%PoCs9SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized Actor

IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

Feb 4, 2000
CVSS5.0v2.0EPSS26.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX