Microsoft IIS 4.0 ISAPI Buffer Overflow Vulnerability
BID:1911
Info
Microsoft IIS 4.0 ISAPI Buffer Overflow Vulnerability
| Bugtraq ID: | 1911 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-1147 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 06 2000 12:00AM |
| Updated: | Jul 11 2009 03:56AM |
| Credit: | Posted to Bugtraq on November 3, 2000 by Marc Maiffret <[email protected]>. |
| Vulnerable: |
Microsoft IIS 4.0 |
| Not Vulnerable: |
Microsoft IIS 5.0 |
Discussion
Microsoft IIS 4.0 ISAPI Buffer Overflow Vulnerability
The ASP ISAPI file parser does not properly execute certain malformed ASP files that contain scripts with the LANGUAGE parameter containing a buffer of over 2200 characters and have the RUNAT value set as 'server'. Depending on the data entered into the buffer, a denial of service attack could be launched or arbitrary code could be executed under the SYSTEM privilege level in the event that a malicious ASP file were locally executed on IIS.
The ASP ISAPI file parser does not properly execute certain malformed ASP files that contain scripts with the LANGUAGE parameter containing a buffer of over 2200 characters and have the RUNAT value set as 'server'. Depending on the data entered into the buffer, a denial of service attack could be launched or arbitrary code could be executed under the SYSTEM privilege level in the event that a malicious ASP file were locally executed on IIS.
Exploit / POC
Microsoft IIS 4.0 ISAPI Buffer Overflow Vulnerability
eEye Digital Security <[email protected]> has released the following exploit:
eEye Digital Security <[email protected]> has released the following exploit:
Solution / Fix
Microsoft IIS 4.0 ISAPI Buffer Overflow Vulnerability
Solution:
This issue has been resolved by a number of Microsoft IIS patches. The patch below will eliminate this vulnerability:
Microsoft IIS 4.0
Solution:
This issue has been resolved by a number of Microsoft IIS patches. The patch below will eliminate this vulnerability:
Microsoft IIS 4.0
References
Microsoft IIS 4.0 ISAPI Buffer Overflow Vulnerability
References:
References: