CVE-2001-0507

EXPLOITED

Internet Information Services 5.0 - Privilege Escalation via Trojan Horse System File

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2001-0507 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Digital Offense.

AI-analyzed exploit summary The provided content is a brief description of a vulnerability in Microsoft IIS 5.0 with a link to an external download (GitLab). No actual exploit code or technical details are included in the text.

Description

IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.

Exploits (1)

exploitdb SUSPICIOUS VERIFIED
by Digital Offense · textlocalwindows
https://www.exploit-db.com/exploits/21072

The provided content is a brief description of a vulnerability in Microsoft IIS 5.0 with a link to an external download (GitLab). No actual exploit code or technical details are included in the text.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Internet Information Services 5.0
Auth required
Prerequisites: Write permissions on the target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6985
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/205069
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/l-132.shtml
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/5607
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912

Scores

EPSS 0.0216
EPSS Percentile 84.7%

Details

VulnCheck KEV 2021-01-05
Status published
Products (1)
microsoft/internet_information_services 5.0
Published Sep 20, 2001
Tracked Since Feb 18, 2026