CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2017-7269

CVSS 9.8v3.1pub. 2017-03-27upd. 2026-04-21

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Internet Information Services

    APP
    Microsoft
    6.0
  • Microsoft Windows Server 2003

    OS
    Microsoft
    r2

CISA KEV — detailsi

Vendori
Microsoft
Producti
Internet Information Services (IIS)
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 maja 2022
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE

CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓same product

Apache Struts 2: RCE przez prefiks action/redirect w parametrach

CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓same product

RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC

CVE-2012-1891CRITICAL9.8PL ✓same product

RCE w Microsoft MDAC/WDAC — heap buffer overflow przez dane XML

CVE-2011-0657CRITICAL9.8PL ✓same product

RCE w kliencie DNS Windows — podatność w przetwarzaniu zapytań DNS (DNSAPI.dll)