Vulnerability in IIS Web Server Allows URL Bypass via Escape Characters
CVE-2000-0024

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
21 December 1999

Summary

The IIS web server exhibits a vulnerability where it fails to properly canonicalize URLs. This oversight enables remote attackers to exploit escape characters to bypass access restrictions enforced by third-party applications. This can result in unauthorized access to sensitive resources, emphasizing the need for robust security measures to prevent exploitation.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.