Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-7269

Quick assessment

Affected
n/a n/a
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Windows Server 2003 R2是美国微软(Microsoft)公司发布的一套服务器操作系统。Internet Information Services(IIS)是一套运行于Microsoft Windows中的互联网基本服务。 Microsoft Windows Server 2003 R2中的IIS 6.0版本中的WebDAV服务的‘ScStoragePathFromUrl’函数存在缓冲区溢出漏洞。远程攻击者可通过发送特制的PROPFIND请求利用该漏洞执行任意代码。

AI Predicted 10.0 Difficulty: Trivial KEV EPSS 99.82% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-7269

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Internet Information Services 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows Server 2003 R2是美国微软(Microsoft)公司发布的一套服务器操作系统。Internet Information Services(IIS)是一套运行于Microsoft Windows中的互联网基本服务。 Microsoft Windows Server 2003 R2中的IIS 6.0版本中的WebDAV服务的‘ScStoragePathFromUrl’函数存在缓冲区溢出漏洞。远程攻击者可通过发送特制的PROPFIND请求利用该漏洞执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-7269

# POC Description Source Link Shenlong Link
1 An exploit for Microsoft IIS 6.0 CVE-2017-7269 https://github.com/eliuha/webdav_exploit POC Details
2 CVE-2017-7269 回显PoC ,用于远程漏洞检测.. https://github.com/lcatro/CVE-2017-7269-Echo-PoC POC Details
3 exec 8 bytes command https://github.com/caicai1355/CVE-2017-7269-exploit POC Details
4 Poc for iis6.0 https://github.com/M1a0rz/CVE-2017-7269 POC Details
5 None https://github.com/whiteHat001/cve-2017-7269picture POC Details
6 fixed msf module for cve-2017-7269 https://github.com/zcgonvh/cve-2017-7269 POC Details
7 iis6 exploit 2017 CVE-2017-7269 https://github.com/g0rx/iis6-exploit-2017-CVE-2017-7269 POC Details
8 Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269) https://github.com/slimpagey/IIS_6.0_WebDAV_Ruby POC Details
9 None https://github.com/homjxi0e/cve-2017-7269 POC Details
10 CVE-2017-7269 https://github.com/xiaovpn/CVE-2017-7269 POC Details
11 CVE-2017-7269 to webshell or shellcode loader https://github.com/zcgonvh/cve-2017-7269-tool POC Details
12 CVE-2017-7269利用代码(rb文件) https://github.com/mirrorblack/CVE-2017-7269 POC Details
13 None https://github.com/Al1ex/CVE-2017-7269 POC Details
14 None https://github.com/ThanHuuTuan/CVE-2017-7269 POC Details
15 None https://github.com/crypticdante/CVE-2017-7269 POC Details
16 CVE-2017-7269 implemented in python3 https://github.com/denchief1/CVE-2017-7269_Python3 POC Details
17 CVE-2017-7269 implemented in C# https://github.com/denchief1/CVE-2017-7269 POC Details
18 None https://github.com/H3xL00m/CVE-2017-7269 POC Details
19 None https://github.com/n3ov4n1sh/CVE-2017-7269 POC Details
20 None https://github.com/c0d3cr4f73r/CVE-2017-7269 POC Details
21 Windows Server 2003 & IIS 6.0 - Remote Code Execution https://github.com/Cappricio-Securities/CVE-2017-7269 POC Details
22 This repository contain an script to exploit CVE-2017-7269 https://github.com/OmarSuarezDoro/CVE-2017-7269 POC Details
23 None https://github.com/Sp3c73rSh4d0w/CVE-2017-7269 POC Details
24 None https://github.com/VanishedPeople/CVE-2017-7269 POC Details
25 None https://github.com/0xwh1pl4sh/CVE-2017-7269 POC Details
26 None https://github.com/N3rdyN3xus/CVE-2017-7269 POC Details
27 None https://github.com/NyxByt3/CVE-2017-7269 POC Details
28 is a PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6 https://github.com/geniuszlyy/CVE-2017-7269 POC Details
29 CVE-2017-7269 https://github.com/AxthonyV/GenWebDavIISExploit POC Details
30 PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6. This tool is designed for educational and research purposes to showcase how the vulnerability can be leveraged to execute arbitrary code on a remote server. https://github.com/AxthonyV/CVE-2017-7269 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-7269

登录查看更多情报信息。

Patches & Fixes for CVE-2017-7269 (1)

Vendor Advisories for CVE-2017-7269 (3)

Exploits & Public PoCs for CVE-2017-7269 (2)

Security Blog Posts for CVE-2017-7269 (1)

Other References for CVE-2017-7269 (3)

Same Patch Batch · n/a · 2017-03-27 · 46 CVEs total

CVE-2017-6459 Windows installer for NTP 缓冲区错误漏洞
CVE-2017-6463 Network Time Protocol 输入验证错误漏洞
CVE-2017-6542 PuTTY 安全漏洞
CVE-2017-7271 Yii Framework 跨站脚本漏洞
CVE-2017-7272 PHP 安全漏洞
CVE-2017-7273 Linux kernel 安全漏洞
CVE-2017-7274 radare2 安全漏洞
CVE-2017-7275 ImageMagick 安全漏洞
CVE-2017-7191 Irssi 安全漏洞
CVE-2017-6460 NTP 缓冲区错误漏洞
CVE-2017-6462 NTP 缓冲区错误漏洞
CVE-2017-6458 NTP 缓冲区错误漏洞
CVE-2017-6455 NTP 安全漏洞
CVE-2017-6452 Windows installer for NTP 缓冲区错误漏洞
CVE-2017-6451 NTP 安全漏洞
CVE-2016-9243 Cryptography HKDF 安全漏洞
CVE-2016-4912 OpenSLP 安全漏洞
CVE-2016-10225 全志H3,A83T和H8 Allwinner 3.4 legacy kernel 权限许可和访问控制问题漏洞
CVE-2015-8764 FreeRADIUS EAP-PWD模块安全漏洞
CVE-2015-8763 FreeRADIUS EAP-PWD模块安全漏洞

Showing top 20 of 46 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2017-7269

No comments yet


Leave a comment