Skip to main content

Microsoft Internet Information Services (IIS) WebDAV Authentication Bypass Vulnerabilities ( 10 June 2009 )

Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 4659 Views

RISK: Medium Risk

1. IIS 5.0 WebDAV Authentication Bypass Vulnerability

An elevation of privilege vulnerability exists in the way that the WebDAV extension for IIS handles HTTP requests. An attacker could exploit this vulnerability by creating a specially crafted anonymous HTTP request to gain access to a location that should require authentication.

2. IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability

An elevation of privilege vulnerability exists in the way that the WebDAV extension for IIS handles HTTP requests. An attacker could exploit this vulnerability by creating a specially crafted anonymous HTTP request to gain access to a location that typically requires authentication.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Microsoft Windows 2000
  • Windows XP
  • Windows Server 2003
  • Microsoft Internet Information Services 5.0
  • Microsoft Internet Information Services 5.1
  • Microsoft Internet Information Services 6.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link