vendor:
IIS
by:
Anonymous
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: IIS
Affected Version From: IIS 7.5
Affected Version To: IIS 10.0
Patch Exists: YES
Related CWE: CVE-2018-8248
CPE: a:microsoft:iis
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2018
IIS Range Header Denial of Service Vulnerability
This exploit is a denial of service vulnerability in Microsoft IIS web server. It is caused by a specially crafted HTTP request with a range header that specifies a very large range. This causes the server to crash and become unresponsive.
Mitigation:
Microsoft has released a patch for this vulnerability. It is recommended to update the server to the latest version.