216.73.216.145

CVE-2017-7269

· Published 27/03/2017 04:59 · Modified 24/07/2026 01:50 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2017-7269

Essential information

Published
27/03/2017 04:59
Modified
24/07/2026 01:50
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
10.0 (v2) 9.8 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CWE-120
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.

NVD status

NVD
View on NVD