VDB
CVE-2017-7269
CVE-2017-7269
PUBLISHED
KEV
CVSS 9.300000190734863 CRITICAL
## Descrição É possível executar código arbitrário ou realizar um ataque de disponibilidade de serviço através de um Buffer Overflow na função ScStoragePathFromUrl do serviço WebDAV presente no Internet Information Service (IIS) 6.0 do Microsoft Windows Server 2003 R2. Para explorar esta vulnerabilidade basta realizar um request alterado usando o método PROPFIND. ## Impacto Um utilizador remoto consegue executar código arbitrário ou realizar um ataque de disponibilidade - Denial of Service (DoS).
EPSS 94.41% · 100.0th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
94.41%
100.0th percentile
Exploit Intelligence
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc-repo)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc)
- Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and privilege escalation to SYSTEM, along with risk analysis and remediation strategies. (github-poc)
…and 328 more exploits
Timeline
- CVE Published
- Mar 27, 2017 PoC Published
- Mar 28, 2017 PoC Published
- May 11, 2017 PoC Published
- May 11, 2017 PoC Published
- Sep 14, 2017 PoC Published
- Jan 10, 2018 PoC Published
- May 29, 2018 PoC Published
- Oct 9, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
References
- https://dyn.cncs.gov.pt/pt/alerta-detalhe/art/134964/alerta-de-vulnerabilidade-iis-60-com-webdav advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7269 technical
- https://www.helpnetsecurity.com/2017/03/30/cve-2017-7269/ technical
- http://blog.trendmicro.com/trendlabs-security-intelligence/iis-6-0-vulnerability-leads-code-execution/ technical
- https://github.com/edwardz246003/IIS_exploit technical
- https://dyn.cncs.gov.pt/pt/alerta-detalhe/art/134975/alerta-de-vulnerabilidades-windows-xp advisory
- http://www.securityweek.com/windows-xp-receives-patches-more-shadow-brokers-exploits technical