Vulnerabilities > CVE-2008-0074 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS08-005.NASL |
description | The remote host contains a version of Microsoft Internet Information Services (IIS) that is vulnerable to a security flaw that could allow a local user to elevate his privileges to SYSTEM due to a bug in the way IIS handles file change notifications in the FTPRoot, NNTPFile\Root and WWWRoot folders. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31039 |
published | 2008-02-12 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/31039 |
title | MS08-005: Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831) |
code |
|
Oval
accepted | 2011-11-14T04:00:29.721-05:00 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
description | Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:5389 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2008-02-14T10:00:19 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
title | Internet Information Services Local Privilege Elevation Vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
version | 38 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 27101 CVE(CAN) ID: CVE-2008-0074 Microsoft Internet信息服务(IIS)是Microsoft Windows自带的一个网络信息服务器,其中包含HTTP服务功能。 IIS处理FTPRoot、NNTPFile\Root和WWWRoot文件夹中文件变化通知的方式存在本地权限提升漏洞,成功利用这个漏洞的攻击者可以在本地系统安全环境中执行任意指令。 Microsoft IIS 7.0 Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 5.0 临时解决方法: * 在Windows Server 2003上停止FTP和NNTP服务: net stop msftpsvc net stop nntpsvc * 对于用于执行用户控制ASP页面的帐号,拒绝对NNTP root、FTP root和WWW root文件夹的写访问: cacls c:\inetpub\ftproot /E /P IUSR_WS2003ENTSP1:R cacls c:\inetpub\ftproot /E /P USERS:R cacls c:\inetpub\nntpfile\root /E /P "ANONYMOUS LOGON":R cacls c:\inetpub\nntpfile\root /E /P EVERYONE:R 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS08-005)以及相应补丁: MS08-005:Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831) 链接:<a href=http://www.microsoft.com/technet/security/Bulletin/MS08-005.mspx?pf=true target=_blank>http://www.microsoft.com/technet/security/Bulletin/MS08-005.mspx?pf=true</a> |
id | SSV:2902 |
last seen | 2017-11-19 |
modified | 2008-02-20 |
published | 2008-02-20 |
reporter | Root |
title | Microsoft IIS文件更改通知本地权限提升漏洞(MS08-005) |
References
- http://marc.info/?l=bugtraq&m=120361015026386&w=2
- http://marc.info/?l=bugtraq&m=120361015026386&w=2
- http://marc.info/?l=bugtraq&m=120361015026386&w=2
- http://marc.info/?l=bugtraq&m=120361015026386&w=2
- http://secunia.com/advisories/28849
- http://secunia.com/advisories/28849
- http://www.securityfocus.com/bid/27101
- http://www.securityfocus.com/bid/27101
- http://www.securitytracker.com/id?1019384
- http://www.securitytracker.com/id?1019384
- http://www.us-cert.gov/cas/techalerts/TA08-043C.html
- http://www.us-cert.gov/cas/techalerts/TA08-043C.html
- http://www.vupen.com/english/advisories/2008/0507/references
- http://www.vupen.com/english/advisories/2008/0507/references
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-005
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5389
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5389