RETIRED: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability
BID:37460
Info
RETIRED: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability
| Bugtraq ID: | 37460 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 23 2009 12:00AM |
| Updated: | Dec 29 2009 09:42PM |
| Credit: | Soroush Dalili |
| Vulnerable: |
Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 Microsoft IIS 3.0 Microsoft IIS 2.0 Microsoft IIS 1.0 |
| Not Vulnerable: |
Microsoft IIS 7.5 |
Discussion
RETIRED: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability
Microsoft IIS is prone to a security-bypass vulnerability.
This vulnerability may cause IIS to interpret unexpected files as CGI applications. Attackers may be able to exploit this vulnerability to bypass intended security restrictions.
UPDATE (December 25, 2009): Reports indicate that IIS 7.5 is not vulnerable to this issue. Furthermore, it is currently unknown whether IIS 7.0 is vulnerable.
UPDATE (December 29, 2009): Reports indicate that IIS 5.0 SP1 under Windows XP SP 3 and IIS 7.0 under Windows Server 2008 are not affected.
NOTE: This BID is being retired. For an exploit to succeed, IIS must be configured in a nondefault way and contrary to the vendor's recommended best practices.
Microsoft IIS is prone to a security-bypass vulnerability.
This vulnerability may cause IIS to interpret unexpected files as CGI applications. Attackers may be able to exploit this vulnerability to bypass intended security restrictions.
UPDATE (December 25, 2009): Reports indicate that IIS 7.5 is not vulnerable to this issue. Furthermore, it is currently unknown whether IIS 7.0 is vulnerable.
UPDATE (December 29, 2009): Reports indicate that IIS 5.0 SP1 under Windows XP SP 3 and IIS 7.0 under Windows Server 2008 are not affected.
NOTE: This BID is being retired. For an exploit to succeed, IIS must be configured in a nondefault way and contrary to the vendor's recommended best practices.
Exploit / POC
RETIRED: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability
An attacker may use readily available tools to carry out an attack.
NOTE: This issue can be exploited using Metasploit Framework's 'msfencode' command.
An attacker may use readily available tools to carry out an attack.
NOTE: This issue can be exploited using Metasploit Framework's 'msfencode' command.
Solution / Fix
RETIRED: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: The vendor is currently investigating the vulnerability and will provide additional details later. Please see the references for more information.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: The vendor is currently investigating the vulnerability and will provide additional details later. Please see the references for more information.
References
RETIRED: Microsoft IIS Malformed Local Filename Security Bypass Vulnerability
References:
References:
- Exploiting Microsoft IIS with Metasploit (Metasploit)
- Microsoft IIS 0Day Vulnerability in Parsing Files (semi-colon bug) (Soroush Dalili)
- Microsoft IIS Homepage (Microsoft)
- New Reports of a Vulnerability in IIS (Microsoft)
- Public disclosure of IIS security issue with semi-colons in URL (naziml)
- Results of Investigation into Holiday IIS Claim (Microsoft)
- Code to mitigate IIS semicolon zero-day ([email protected])
- Microsoft IIS 0Day Vulnerability in Parsing Files (semi-colon bug) ([email protected])
- Tests about semicolon zero-day (BID 37460) (Crash - DcLabs
)