The URL parser in Microsoft Internet Information Services (IIS) 5.1...
Vulnerability Description
The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as demonstrated using "/_vti_bin/.dll/*/~0". NOTE: the consequence was originally believed to be only a denial of service (application crash and reboot).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-4360
Credits & Attribution
No credits recorded in the NVD database.
References
- http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html
- http://www.securityfocus.com/archive/1/419707/100/0/threaded
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1703
- http://securityreason.com/securityalert/271
- http://securitytracker.com/alerts/2005/Dec/1015376.html
- http://www.osvdb.org/21805
- http://ingehenriksen.blogspot.com/2005/12/microsoft-iis-remote-dos-dll-url.html
- http://www.vupen.com/english/advisories/2005/2963
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-041
- http://www.securityfocus.com/bid/15921
- http://www.us-cert.gov/cas/techalerts/TA07-191A.html
- http://secunia.com/advisories/18106
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.