Security News > 2017 > March > Actively exploited zero-day in IIS 6.0 affects 60,000+ servers (Help Net Security)
Microsoft Internet Information Services (IIS) 6.0 sports a zero-day vulnerability (CVE-2017-7269) that was exploited in the wild last summer and is likely also being exploited by threat actors at this very moment. It is a buffer overflow flaw in a function in the WebDAV service in IIS 6.0 in Microsoft Windows Server 2003 R2, and can be triggered by attackers sending a overlong IF header in a PROPFIND request. Unfortunately, the flaw won’t be patched … More →
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/1Ypo5y1MD8Y/
Related news
- Rackspace internal monitoring web servers hit by zero-day (source)
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- The Rise of Zero-Day Vulnerabilities: Why Traditional Security Solutions Fall Short (source)
- Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation (source)
- 'Alarming' security bugs lay low in Linux's needrestart server utility for 10 years (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-03-27 | CVE-2017-7269 | Classic Buffer Overflow vulnerability in Microsoft Internet Information Server 6.0 Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016. | 9.8 |