CVE-2008-0074
Summary
| CVE | CVE-2008-0074 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-02-12 21:00:00 UTC |
| Updated | 2021-02-05 15:37:00 UTC |
| Description | Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders. |
Risk And Classification
Problem Types: CWE-264 | NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Information Server | 6.0 | All | All | All |
| Application | Microsoft | Internet Information Server | 6.0 | beta | All | All |
| Application | Microsoft | Internet Information Server | 6.0 | All | All | All |
| Application | Microsoft | Internet Information Server | 6.0 | beta | All | All |
| Application | Microsoft | Internet Information Services | 5.0 | All | All | All |
| Application | Microsoft | Internet Information Services | 5.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft IIS File Change Notification Local Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| Microsoft Security Bulletin MS08-005 - Important | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft Internet Information Services Privilege Escalation - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| HPSBST02314 | HP | marc.info | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| US-CERT Technical Cyber Security Alert TA08-043C -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| SecurityTracker.com Archives - Microsoft Internet Information Services File Change Notification Bug Lets Local Users Gain Elevated Privileges | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.