IIS 8.0 and 8.5 Wildcard Rule Processing Flaw in Microsoft's HTTP Server
CVE-2014-4078
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 11 November 2014
What is CVE-2014-4078?
The IP Security feature in Microsoft Internet Information Services (IIS) versions 8.0 and 8.5 is susceptible to a bypass due to improper processing of wildcard allow and deny rules. This vulnerability allows attackers to exploit the 'IP Address and Domain Restrictions' feature, enabling them to send crafted HTTP requests that circumvent the intended security rules. As a result, unauthorized access may be gained, exposing the server to potential attacks. Proper configuration and patching are essential to mitigate this risk.