search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Microsoft IIS FTP server memory corruption vulnerability

Vulnerability Note VU#842372

Original Release Date: 2010-12-22 | Last Revised: 2010-12-23

Overview

Microsoft IIS FTP server 7.5 is affected by a pre-authentication memory corruption vulnerability.

Description

A specifically crafted request sent to the IIS FTP service can result in memory corruption causing the service to crash. A denial-of-service exploit has been released to the public. IIS 7.5.7600.16385 on Windows 7 is reported to be affected. Other versions may also be affected. Additional details are available on Microsoft's Security Research & Defense blog.

Impact

An attacker can cause a denial of service. Depending on the specifics of the vulnerability, an attacker could potentially execute arbitrary code.

Solution

We are currently unaware of a practical solution to this problem.

Restrict Access

Appropriate firewall rules should be implemented to restrict access to trusted sources. Customers of IPS vendors should request updated signatures for this vulnerability and block related traffic.

Vendor Information

842372
 

Microsoft Corporation Affected

Updated:  December 22, 2010

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported to the public by Matthew Bergin via Exploit-DB.

This document was written by Jared Allar.

Other Information

CVE IDs: None
Severity Metric: 1.77
Date Public: 2010-12-21
Date First Published: 2010-12-22
Date Last Updated: 2010-12-23 15:22 UTC
Document Revision: 11

Sponsored by CISA.