CVE-2009-2521

EXPLOITED RANSOMWARE

Microsoft IIS 5.0-7.0 - DoS

Title source: llm

Description

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."

Exploits (3)

exploitdb WORKING POC
by Myo Soe · rubydoswindows
https://www.exploit-db.com/exploits/17476
metasploit WORKING POC
by Kingcope, Myo Soe · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/ftp/iis_list_exhaustion.rb
exploitdb WORKING POC VERIFIED
by kingcope · textdoswindows
https://www.exploit-db.com/exploits/9587

Scores

EPSS 0.6078
EPSS Percentile 98.3%

Exploitation Intel

VulnCheck KEV 2023-02-14
Ransomware Use Confirmed

Classification

CWE
CWE-400
Status draft

Affected Products (1)

microsoft/internet_information_services < 7.0

Timeline

Published Sep 04, 2009
Tracked Since Feb 18, 2026