CVE-2017-7269

CRITICAL KEV NUCLEI

IIS 6.0 - Buffer Overflow

Title source: llm

Description

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

Exploits (33)

nomisec WORKING POC 135 stars
by zcgonvh · remote
https://github.com/zcgonvh/cve-2017-7269
nomisec STUB 92 stars
by g0rx · remote
https://github.com/g0rx/iis6-exploit-2017-CVE-2017-7269
nomisec WORKING POC 89 stars
by lcatro · remote
https://github.com/lcatro/CVE-2017-7269-Echo-PoC
nomisec WORKING POC 88 stars
by zcgonvh · remote
https://github.com/zcgonvh/cve-2017-7269-tool
nomisec WORKING POC 22 stars
by eliuha · remote
https://github.com/eliuha/webdav_exploit
nomisec WORKING POC 11 stars
by Al1ex · remote
https://github.com/Al1ex/CVE-2017-7269
nomisec WORKING POC 5 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2017-7269
nomisec WORKING POC 5 stars
by slimpagey · remote
https://github.com/slimpagey/IIS_6.0_WebDAV_Ruby
nomisec WORKING POC 4 stars
by geniuszly · remote
https://github.com/geniuszly/CVE-2017-7269
github WORKING POC 2 stars
by BasyacatX · pythonpoc
https://github.com/BasyacatX/CVE-2024-32002-PoC_Chinese/tree/main/CVE-2017-7269_PoC.py
github WORKING POC 1 stars
by vaishakhcv · perlpoc
https://github.com/vaishakhcv/CVE-exploits/tree/master/CVE-2017-7269
nomisec WORKING POC 1 stars
by caicai1355 · remote
https://github.com/caicai1355/CVE-2017-7269-exploit
nomisec WORKING POC 1 stars
by nika0x38 · remote
https://github.com/nika0x38/CVE-2017-7269
nomisec SCANNER 1 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2017-7269
nomisec WORKING POC
by Killian0713 · poc
https://github.com/Killian0713/Assignement_3-CVE-2017-7269
nomisec SCANNER
by ThanHuuTuan · remote
https://github.com/ThanHuuTuan/CVE-2017-7269
nomisec WRITEUP
by homjxi0e · poc
https://github.com/homjxi0e/cve-2017-7269
nomisec WORKING POC
by VanishedPeople · remote
https://github.com/VanishedPeople/CVE-2017-7269
github WORKING POC
by winterwolf32 · perlpoc
https://github.com/winterwolf32/CVE_Exploits-/tree/master/CVE-2017-7269
nomisec NO CODE
by denchief1 · poc
https://github.com/denchief1/CVE-2017-7269
nomisec NO CODE
by whiteHat001 · poc
https://github.com/whiteHat001/cve-2017-7269picture
patchapalooza WORKING POC
by n3rdh4x0r · remote
https://github.com/n3rdh4x0r/CVE-2017-7269
patchapalooza WORKING POC
by liuziyann · poc
https://gitee.com/liuziyann/CVE-2017-7269
patchapalooza WORKING POC
by kiang70 · poc
https://gitee.com/kiang70/CVE-2017-7269-Echo-PoC
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/41992
exploitdb WORKING POC
by Zhiniang Peng & Chen Wu · pythonremotewindows
https://www.exploit-db.com/exploits/41738
metasploit WORKING POC MANUAL
by Zhiniang Peng, Chen Wu, Dominic Chell <[email protected]>, firefart, zcgonvh <[email protected]>, Rich Whitcroft, Lincoln · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/iis/iis_webdav_scstoragepathfromurl.rb

Nuclei Templates (1)

Windows Server 2003 & IIS 6.0 - Remote Code Execution
CRITICALby thomas_from_offensity,geeknik
Shodan: cpe:"cpe:2.3:a:microsoft:internet_information_server"

Scores

CVSS v3 9.8
EPSS 0.9441
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2021-11-03
VulnCheck KEV 2017-03-27
InTheWild.io 2019-07-03
ENISA EUVD EUVD-2017-16299

Classification

CWE
CWE-120
Status draft

Affected Products (1)

microsoft/internet_information_services

Timeline

Published Mar 27, 2017
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026