Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.140228
Categoría:Web Servers
Título:Microsoft Internet Information Services Buffer Overflow Vulnerability
Resumen:Microsoft Internet Information Services is prone to a buffer overflow; vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an; insufficiently sized memory buffer.
Descripción:Summary:
Microsoft Internet Information Services is prone to a buffer overflow
vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an
insufficiently sized memory buffer.

Vulnerability Impact:
Attackers can exploit this issue to execute arbitrary code in the context
of the affected application. Failed exploit attempts will result in denial-of-service conditions.

Affected Software/OS:
Microsoft Internet Information Services 6.0 running on Microsoft Windows Server 2003 R2 is vulnerable, other versions may also be affected.

Solution:
Microsoft has addressed this issue and provided an update.
Head over to the references and download and install the necessary update for your system.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-7269
BugTraq ID: 97127
http://www.securityfocus.com/bid/97127
https://www.exploit-db.com/exploits/41738/
https://www.exploit-db.com/exploits/41992/
https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html
https://github.com/danigargu/explodingcan
https://github.com/edwardz246003/IIS_exploit
https://github.com/rapid7/metasploit-framework/pull/8162
https://medium.com/@iraklis/number-of-internet-facing-vulnerable-iis-6-0-to-cve-2017-7269-8bd153ef5812
http://www.securitytracker.com/id/1038168
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.