CVE-2010-1899

Microsoft Internet Information Server - Memory Corruption

Title source: rule

Description

Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by kingcope · textdoswindows
https://www.exploit-db.com/exploits/15167
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/http/ms10_065_ii6_asp_dos.rb

Scores

EPSS 0.8596
EPSS Percentile 99.4%

Details

CWE
CWE-119
Status published
Products (2)
microsoft/internet_information_server 6.0
microsoft/internet_information_services 7.5
Published Sep 15, 2010
Tracked Since Feb 18, 2026