Security News > 2017 > March > Actively exploited zero-day in IIS 6.0 affects 60,000+ servers (Help Net Security)

Actively exploited zero-day in IIS 6.0 affects 60,000+ servers (Help Net Security)
2017-03-30 14:15

Microsoft Internet Information Services (IIS) 6.0 sports a zero-day vulnerability (CVE-2017-7269) that was exploited in the wild last summer and is likely also being exploited by threat actors at this very moment. It is a buffer overflow flaw in a function in the WebDAV service in IIS 6.0 in Microsoft Windows Server 2003 R2, and can be triggered by attackers sending a overlong IF header in a PROPFIND request. Unfortunately, the flaw won’t be patched … More →


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/1Ypo5y1MD8Y/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2017-03-27 CVE-2017-7269 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Internet Information Server 6.0
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
network
low complexity
microsoft CWE-119
critical
9.8