CVE-2017-7269: Microsoft Windows Server Buffer Overflow Vulnerability
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
Other sources
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
— CISA
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7269?
CVE-2017-7269 has a high severity rating due to its potential for allowing remote code execution.
How do I fix CVE-2017-7269?
To mitigate CVE-2017-7269, you should apply the relevant security patches provided by Microsoft for IIS 6.0.
Which products are affected by CVE-2017-7269?
CVE-2017-7269 affects Microsoft Internet Information Services (IIS) version 6.0 running on Windows Server 2003 R2.
Can CVE-2017-7269 be exploited remotely?
Yes, CVE-2017-7269 can be exploited remotely through a crafted PROPFIND request sent to the WebDAV service.
What type of attack does CVE-2017-7269 facilitate?
CVE-2017-7269 facilitates buffer overflow attacks that can lead to arbitrary code execution.