Microsoft IIS Authentication Remote Code Execution Vulnerability
BID:40573
Info
Microsoft IIS Authentication Remote Code Execution Vulnerability
| Bugtraq ID: | 40573 |
| Class: | Unknown |
| CVE: |
CVE-2010-1256 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2010 12:00AM |
| Updated: | Jul 05 2010 04:17PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Microsoft IIS 7.5 Microsoft IIS 7.0 Microsoft IIS 6.0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS Authentication Remote Code Execution Vulnerability
Microsoft IIS is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects IIS 6.0, 7.0 and 7.5.
Microsoft IIS is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects IIS 6.0, 7.0 and 7.5.
Exploit / POC
Microsoft IIS Authentication Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft IIS Authentication Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft IIS 6.0
Microsoft IIS 7.0
Microsoft IIS 7.5
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft IIS 6.0
-
Microsoft Security Update for Windows Server 2003 (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=0761C207-5465 -4F42-B61F-BD02EFCEF27D -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=F1F3E524-8AC6 -4210-A3A8-4FFC58A606EA -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=023572FF-CE5D -4428-A96B-1245DB6FF312
Microsoft IIS 7.0
-
Microsoft Security Update for Windows Server 2008 (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=84A54246-5D9E -49E2-8170-AF48B43F984D -
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=8AD19EBA-9821 -48B4-A942-4EE4F002F913 -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=38286E43-89A6 -4895-8FF9-69452DF38706 -
Microsoft Security Update for Windows Vista (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=01382926-2313 -4769-A0A5-262C4F9F18A1 -
Microsoft Security Update for Windows Vista for x64-based Systems (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=7FB6F2B8-C7A6 -4239-99F3-CF3AACF89B0F
Microsoft IIS 7.5
-
Microsoft Security Update for Windows 7 (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=588167CB-F62A -4FB8-8A18-AC15DC322495 -
Microsoft Security Update for Windows 7 for x64-based Systems (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=1C45D0C8-1629 -470B-8167-C6BF66054595 -
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=869E900A-0063 -4D8B-9B7C-7D12F6BE12CD -
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB982666)
http://www.microsoft.com/downloads/details.aspx?familyid=5D9B7705-6280 -4D2E-94FA-3160B3CE5CFA
References
Microsoft IIS Authentication Remote Code Execution Vulnerability
References:
References: