Executive brief
Microsoft Internet Information Services (IIS), a web server used to host websites and applications, is vulnerable to a denial-of-service attack. By sending a specially crafted, excessively long web address (URL) to the server, an attacker can cause the service to crash or become unresponsive. This can lead to website downtime, preventing customers and employees from accessing hosted services.
Technical details
A denial-of-service vulnerability exists in Microsoft Internet Information Services (IIS) 2.0 due to improper handling of long URL requests. An unauthenticated remote attacker can exploit this by sending a GET request containing an excessively long string to the web server. This triggers a resource exhaustion or crash condition within the service, leading to a loss of availability. The vulnerability is reachable over the network without user interaction. While specific patch details are dated, modern versions of IIS are not affected by this legacy issue.
Affected products
- Microsoft Internet Information Services (IIS) 2.0
Timeline
- 1997-06-01: disclosed