Integer Overflow Vulnerability in Microsoft IIS Internet Printing Protocol
CVE-2008-1446
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 15 October 2008
What is CVE-2008-1446?
An integer overflow in the Internet Printing Protocol (IPP) ISAPI extension within Microsoft Internet Information Services (IIS) 5.0 through 7.0 can be exploited by remote authenticated users. By crafting a malicious HTTP POST request, an attacker can trigger an outbound IPP connection, potentially allowing arbitrary code execution on the server. This vulnerability affects various Windows platforms, including Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008. Users and administrators are advised to apply the latest security updates to mitigate this risk.