Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
BID:36273
Info
Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
| Bugtraq ID: | 36273 |
| Class: | Unknown |
| CVE: |
CVE-2009-2521 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Oct 13 2009 08:58PM |
| Credit: | Kingcope |
| Vulnerable: |
Microsoft IIS 7.0 Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 5.0 |
| Not Vulnerable: |
Microsoft IIS 7.5 |
Discussion
Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
Microsoft IIS is prone to a denial-of-service vulnerability affecting the application's FTP server.
An attacker can exploit this issue to terminate the affected application, denying service to legitimate users.
This issue affects the following:
IIS 5.0
IIS 5.1
IIS 6.0
IIS 7.0
NOTE: Microsoft IIS 7.0 with FTP Service 7.5 is not affected by this issue.
Microsoft IIS is prone to a denial-of-service vulnerability affecting the application's FTP server.
An attacker can exploit this issue to terminate the affected application, denying service to legitimate users.
This issue affects the following:
IIS 5.0
IIS 5.1
IIS 6.0
IIS 7.0
NOTE: Microsoft IIS 7.0 with FTP Service 7.5 is not affected by this issue.
Exploit / POC
Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
Microsoft has reported limited in-the-wild exploitation of this issue.
The following example command is available:
ls "-R p*/../"
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Microsoft has reported limited in-the-wild exploitation of this issue.
The following example command is available:
ls "-R p*/../"
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
References:
References:
- Microsoft IIS Homepage (Microsoft)
- Microsoft Security Advisory 975191 Released (Microsoft Security Response Center)
- Microsoft Security Advisory 975191 Revised (Microsoft)
- New vulnerability in IIS5 and IIS6 (Microsoft Security Research & Defense)
- Microsoft Internet Information Services 5.0/6.0 FTP SERVER DENIAL OF SERVICE (Nikolaos Rangos)
- Microsoft Internet Information Services 5.0/6.0 FTP SERVER DENIAL OF SERVICE ('S (Kingcope
) - Microsoft Security Advisory (975191) Vulnerability in Internet Information Servi (Microsoft)
- Microsoft Security Bulletin MS09-053 (Microsoft)