Stack Consumption Vulnerability in Microsoft IIS FTP Service
CVE-2009-2521

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
4 September 2009

What is CVE-2009-2521?

A vulnerability in the FTP Service of Microsoft Internet Information Services (IIS) 5.0 through 7.0 can be exploited by remote authenticated users to induce a denial of service. This occurs through the 'ls -R' command that includes a wildcard aimed at a subdirectory, succeeded by a '..' sequence. Successful exploitation can lead to the crashing of the FTP daemon, disrupting service availability. Administrators are advised to apply the relevant patches to mitigate this risk.

References

EPSS Score

60% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.