Executive brief
A stack-based buffer overflow vulnerability exists in the ScStoragePathFromUrl function within the WebDAV service of Microsoft IIS 6.0. Remote attackers can exploit this by sending a specially crafted PROPFIND request containing a long 'If' header, leading to arbitrary code execution.
Affected products
- Microsoft Internet Information Services (IIS) 6.0 6.0
- Microsoft Windows Server 2003 R2 R2
Timeline
- 2016-07: exploited: Exploited in the wild as early as July or August 2016.
- 2017-03-26: disclosed: Initial public disclosure of the vulnerability.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.