CVE-2000-0770

Internet Information Services 4.0 and 5.0 - Unauthenticated File Access Bypass via Permission Canonicalization

Title source: llm
STIX 2.1

Description

IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.

References (2)

Core 2
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1565

Scores

EPSS 0.1419
EPSS Percentile 96.2%

Details

Status published
Products (2)
microsoft/internet_information_server 4.0
microsoft/internet_information_services 5.0
Published Oct 20, 2000
Tracked Since Feb 18, 2026