First published: Thu Sep 20 2001(Updated: )
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0507 is considered a critical vulnerability as it allows local users to gain elevated privileges.
To fix CVE-2001-0507, ensure that security updates for IIS 5.0 are applied and restrict access to sensitive system files.
CVE-2001-0507 affects local users of Microsoft Internet Information Services version 5.0.
The implications of CVE-2001-0507 include potential unauthorized access and privilege escalation on systems running IIS 5.0.
Yes, CVE-2001-0507 can be exploited easily by local users familiar with the system file structure.