9

CVE-2009-3023

Exploit
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Information Server Version >= 5.0 <= 6.0
   Microsoft ≫ Windows 2000 Version - Update sp4
   Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 90.91% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

http://www.us-cert.gov/cas/techalerts/TA09-286A.html
Third Party Advisory
US Government Resource
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ975191
http://www.exploit-db.com/exploits/9541
Third Party Advisory
Exploit
VDB Entry
http://www.exploit-db.com/exploits/9559
Third Party Advisory
Exploit
VDB Entry
http://www.kb.cert.org/vuls/id/276653
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/36189
Third Party Advisory
Exploit
VDB Entry
http://www.vupen.com/english/advisories/2009/2481
Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-053
Patch
Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6080
Third Party Advisory