CVE-2006-6579

Microsoft Windows XP - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/454268/100/0/threaded

Scores

EPSS 0.0132
EPSS Percentile 68.2%

Details

Status published
Products (5)
microsoft/internet_information_server 3.0
microsoft/internet_information_server 4.0 (2 CPE variants)
microsoft/internet_information_server < 5.0
microsoft/internet_information_services 1.0
microsoft/internet_information_services 2.0
Published Dec 15, 2006
Tracked Since Feb 18, 2026