Executive brief
Certain web servers running on Microsoft Windows contain a flaw that allows unauthorized users to access restricted files. By using specifically crafted long filenames in web requests, an attacker can bypass security checks intended to protect sensitive data. This could lead to the exposure of private information or the unauthorized modification of website content.
Technical details
This vulnerability involves an authentication and access control bypass in various Windows-based web servers. The flaw is rooted in how the server handles file system requests involving long filenames, which can be used to circumvent security filters or access control lists (ACLs) that expect standard 8.3 or short-form naming conventions. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request for a file using its long filename alias. Successful exploitation allows the attacker to read or potentially modify files that should otherwise be restricted by the server's configuration.
Affected products
- Microsoft Windows-based Web Servers
Timeline
- 1998-02-06: disclosed