Microsoft IIS Out Of Process Privilege Escalation Vulnerability
BID:6069
Info
Microsoft IIS Out Of Process Privilege Escalation Vulnerability
| Bugtraq ID: | 6069 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2002-0869 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to Li0n of A3 Security Consulting Co., Ltd. ( http://www.a3sc.co.kr). |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS Out Of Process Privilege Escalation Vulnerability
A vulnerability has been reported for Microsoft IIS that may allow an attacker to obtain elevated privileges. This vulnerability can be exploited by an attacker to load and execute applications on the vulnerable server with SYSTEM level privileges. This vulnerability can exploited when IIS is configured to run applications out of process by modifying the memory space of the dllhost.exe process.
This vulnerability was originally described in BugTraq ID 6068. It is now being assigned its own BugTraq ID.
A vulnerability has been reported for Microsoft IIS that may allow an attacker to obtain elevated privileges. This vulnerability can be exploited by an attacker to load and execute applications on the vulnerable server with SYSTEM level privileges. This vulnerability can exploited when IIS is configured to run applications out of process by modifying the memory space of the dllhost.exe process.
This vulnerability was originally described in BugTraq ID 6068. It is now being assigned its own BugTraq ID.
Exploit / POC
Microsoft IIS Out Of Process Privilege Escalation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS Out Of Process Privilege Escalation Vulnerability
References:
References: