Junglewise Threat Intelligence

CVE-2017-7269: Microsoft Windows Server Buffer Overflow Vulnerability

CVE-2017-7269 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Internet Information Services (Iis). Vendors: Microsoft.

Executive brief

A stack-based buffer overflow vulnerability exists in the ScStoragePathFromUrl function within the WebDAV service of Microsoft IIS 6.0. Remote attackers can exploit this by sending a specially crafted PROPFIND request containing a long 'If' header, leading to arbitrary code execution.

Affected products

  • Microsoft Internet Information Services (IIS) 6.0 6.0
  • Microsoft Windows Server 2003 R2 R2

Timeline

  • 2016-07: exploited: Exploited in the wild as early as July or August 2016.
  • 2017-03-26: disclosed: Initial public disclosure of the vulnerability.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.