First published: Thu Sep 20 2001(Updated: )
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0506 is considered a high severity vulnerability due to its potential to allow local users to gain system privileges.
To fix CVE-2001-0506, it is recommended to upgrade to a patched version of Internet Information Services or apply any relevant security updates from Microsoft.
CVE-2001-0506 affects IIS 5.0 and Internet Information Server 4.0.
CVE-2001-0506 enables privilege escalation attacks through a buffer overflow vulnerability.
CVE-2001-0506 can be exploited by local users with access to the affected IIS environments.