CVE-2001-0507: High severity Microsoft Internet Information Services vulnerability
Published Sep 20, 2001
·Updated
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
Affected Software
1 affected component
Microsoft Internet Information Services=5.0
Event History
Sep 20, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0507?
CVE-2001-0507 is considered a critical vulnerability as it allows local users to gain elevated privileges.
2
How do I fix CVE-2001-0507?
To fix CVE-2001-0507, ensure that security updates for IIS 5.0 are applied and restrict access to sensitive system files.
3
Who is affected by CVE-2001-0507?
CVE-2001-0507 affects local users of Microsoft Internet Information Services version 5.0.
4
What are the implications of CVE-2001-0507?
The implications of CVE-2001-0507 include potential unauthorized access and privilege escalation on systems running IIS 5.0.
5
Is CVE-2001-0507 easy to exploit?
Yes, CVE-2001-0507 can be exploited easily by local users familiar with the system file structure.