Denial of Service Vulnerability in Microsoft IIS
CVE-2007-0087

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
5 January 2007

Summary

Microsoft Internet Information Services (IIS) is vulnerable to a denial of service attack when accessed through a TCP connection with an unusually large window size. This vulnerability allows remote attackers to exploit the server by sending a Range header that includes multiple duplicates of the same data fragment, which can lead to excessive consumption of network bandwidth. Although some experts have argued that the required configurations for this attack are uncommon, the potential for disruption emphasizes the importance of securing IIS installations against such network-oriented threats.

References

EPSS Score

33% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.