vendor:
IIS
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: IIS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Microsoft IIS Denial of Service Vulnerability
Microsoft IIS is prone to denial of service attacks by local users. This issue is exploitable if the local attacker can create an .asp file which makes calls to various devices names. The local attacker must of course possess the privileges required to create such files. The end result of exploiting this vulnerability is that the server will crash and a denial of services will occur. The affected services must be restarted to regain normal functionality.
Mitigation:
Restrict access to the server to trusted users and ensure that all users have the least privileges necessary to perform their tasks.