Executive brief
A vulnerability in a legacy Microsoft IIS component allows remote users to overwrite files on the web server. This component is part of the system used to manage web-based data sources. An attacker could exploit this to corrupt system files or modify website content, potentially leading to a loss of data integrity or unauthorized site changes.
Technical details
The vulnerability exists in the newdsn.exe CGI script, which is part of the Microsoft Internet Information Services (IIS) suite. The script fails to properly validate or restrict file operations, allowing a remote, unauthenticated attacker to overwrite arbitrary files on the host system via a network request. This is a file manipulation vulnerability that can lead to unauthorized modification of data or system configuration. The attack is reachable over the network without requiring user interaction or prior authentication.
Affected products
- Microsoft Internet Information Services (IIS)
Timeline
- 1997-09-01: disclosed