Microsoft Internet Information Services (IIS) FTP Buffer Overflow Vulnerability
RISK: Medium Risk
A vulnerability has been identified in Microsoft Internet Information Services (IIS), which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the "TELNET_STREAM_CONTEXT::OnSendData()" function within the protocol handler (ftpsvc.dll) for the FTP Service when processing user-supplied FTP requests, which could allow remote unauthenticated attackers to crash an affected server or execute arbitrary code with elevated privileges by sending an overly long and malformed packet to an affected FTP server.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- Microsoft Internet Information Services (IIS) versions 7.x
Solutions
There is no patch available for this vulnerability currently.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with