Multiple Microsoft IIS Vulnerabilities
BID:6068
Info
Multiple Microsoft IIS Vulnerabilities
| Bugtraq ID: | 6068 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1181 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Li0n of A3 Security Consulting Co., Ltd. ( http://www.a3sc.co.kr), Mark Litchfield of Next Generation Security Software Ltd. (http://www.nextgenss.com), and Luciano Martins of Deloitte & Touche Argentina (http://www.deloitte.com.ar) are credited for these |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Multiple Microsoft IIS Vulnerabilities
Microsoft Internet Information Services (IIS) is prone to multiple vulnerabilities.
The first vulnerability may allow an attacker to obtain elevated privileges. This vulnerability can be exploited by an attacker to load and execute applications on the vulnerable server with SYSTEM level privileges. This vulnerability can exploited when IIS is configured to run applications out of process.
The second vulnerability may allow a remote attacker to cause a denial of service condition. This vulnerability is related to how IIS allocates memory for WebDAV requests. Any specially crafted WebDAV requests may result in IIS allocating an extremely large amount of memory on the server. Several malformed requests sent to the server will result in the vulnerable system failing to respond to further legitimate requests for service. This vulnerability affects IIS 5.0 and 5.1 only.
The third vulnerability may allow a remote attacker to upload a file onto the vulnerable server and possibly execute it. The vulnerability is a result of inappropriate listing of file types that are subject to the script source access permission in IIS 5.0. As a result an attacker may be able to upload malicious files to a vulnerable server and possibly execute it. This vulnerability only affects IIS 5.0.
The final vulnerability is a cross site scripting vulnerability. The vulnerability is a result of improper sanitization of user-supplied input by IIS. Several web pages, provided by IIS for administrative purposes do not adequately sanitize user-supplied input. Any malicious HTML code that may be included in the URI will be executed.
Microsoft Internet Information Services (IIS) is prone to multiple vulnerabilities.
The first vulnerability may allow an attacker to obtain elevated privileges. This vulnerability can be exploited by an attacker to load and execute applications on the vulnerable server with SYSTEM level privileges. This vulnerability can exploited when IIS is configured to run applications out of process.
The second vulnerability may allow a remote attacker to cause a denial of service condition. This vulnerability is related to how IIS allocates memory for WebDAV requests. Any specially crafted WebDAV requests may result in IIS allocating an extremely large amount of memory on the server. Several malformed requests sent to the server will result in the vulnerable system failing to respond to further legitimate requests for service. This vulnerability affects IIS 5.0 and 5.1 only.
The third vulnerability may allow a remote attacker to upload a file onto the vulnerable server and possibly execute it. The vulnerability is a result of inappropriate listing of file types that are subject to the script source access permission in IIS 5.0. As a result an attacker may be able to upload malicious files to a vulnerable server and possibly execute it. This vulnerability only affects IIS 5.0.
The final vulnerability is a cross site scripting vulnerability. The vulnerability is a result of improper sanitization of user-supplied input by IIS. Several web pages, provided by IIS for administrative purposes do not adequately sanitize user-supplied input. Any malicious HTML code that may be included in the URI will be executed.
Exploit / POC
Multiple Microsoft IIS Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Microsoft IIS Vulnerabilities
Solution:
Fixes available:
Microsoft IIS 5.1
Microsoft IIS 4.0
Microsoft IIS 5.0
Solution:
Fixes available:
Microsoft IIS 5.1
-
Microsoft Q327696: Internet Information Services Security Roll-up Package
For 64-bit versions of Windows XP.
http://download.microsoft.com/download/whistler/Patch/Q327696/W64XP/EN -US/Q327696_WXP_SP2_ia64_ENU.exe -
Microsoft Q327696: Internet Information Services Security Roll-up Package
For 32-bit versions of Windows XP.
http://download.microsoft.com/download/whistler/Patch/Q327696/WXP/EN-U S/Q327696_WXP_SP2_x86_ENU.exe
Microsoft IIS 4.0
-
Microsoft Q327696: Internet Information Services Security Roll-up Package
http://www.microsoft.com/ntserver/nts/downloads/security/q327696/defau lt.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43566%26re direct%3Dno
Microsoft IIS 5.0
-
Microsoft Q327696: Internet Information Services Security Roll-up Package
http://www.microsoft.com/windows2000/downloads/security/q327696/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43296%26red irect%3Dno