Blog | G5 Cyber Security

Millions of websites affected by unpatched flaw in Microsoft IIS 6 web server

A proof-of-concept exploit has been published for an unpatched vulnerability in Microsoft Internet Information Services 6.0. The vulnerability is a buffer overflow in the ScStoragePathFromUrl function of the IIS WebDAV service. It can be exploited through a specially crafted PROPFIND request. Security firm ACROS Security has also developed a free “micropatch” for this vulnerability — an unofficial patch that can be applied without restarting the affected server or IIS process.”]

Source: https://www.csoonline.com/article/3186758/millions-of-websites-affected-by-unpatched-flaw-in-microsoft-iis-6-web-server.html

Exit mobile version