VulDB: Microsoft IIS up to 7.5 File Name Tilde Handler privilege escalation
General

scipID: 5623
Affected: Microsoft IIS up to 7.5
Published: 06/30/2012 (Soroush Dalili & Ali Abbasnejad)
Risk:
critical
Entry: 92.9% complete
Created: 07/03/2012
Updated: 07/04/2012
Summary
A vulnerability classified as critical was found in Microsoft IIS up to 7.5. Affected by this vulnerability is an unknown function of the component File Name Tilde Handler. The manipulation with the input value ::$Index_Allocation leads to a privilege escalation vulnerability. As an impact it is known to affect confidentiality, and integrity.
The weakness was presented 06/30/2012 by Soroush Dalili & Ali Abbasnejad as 19527 as document (Exploit-DB). The advisory is shared for download at exploit-db.com. The vendor was not invovled in the public release. The attack can be launched remotely. The exploitation doesn’t need any form of authentication. Technical details and also a public exploit are known. Due to its background and reception, this vulnerability has a historic impact.
An exploit has been developed by Soroush Dalili & Ali Abbasnejad and been published immediately after the advisory. It is declared as proof-of-concept. The exploit is shared for download at exploit-db.com.
It is possible to mitigate the weakness by firewalling Web Server Port. The problem might be mitigated by replacing the product with Apache as an alternative. The best possible mitigation is suggested to be upgrading to the latest version. The vulnerability is also documented in the vulnerability database at SecurityFocus (BID 54251). Additional details are provided at packetstormsecurity.org.CVSS
Base Score: 5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N) [?]
| Access Vector | Access Complexity | Authentication | Confidentiality | Integrity | Availability |
|---|---|---|---|---|---|
| Local | High | Multiple | None | None | None |
| Adjacent | Medium | Single | Partial | Partial | Partial |
| Network | Low | None | Complete | Complete | Complete |
Exploiting
Class: Privilege escalation
Local: No
Remote: Yes
Availability: Yes
Access: Public
Status: Proof-of-Concept
Author: Soroush Dalili & Ali Abbasnejad
Download: exploit-db.com
Exploit-DB: 19527
Countermeasures
Recommended: Upgrade
0-Day Time: 0 days since found
Exploit Delay Time: 0 days since known
Firewalling: Web Server Port
Alternative: Apache
Timeline
06/30/2012 | Advisory disclosed
06/30/2012 | Exploit disclosed
07/03/2012 | VulDB entry created
07/04/2012 | VulDB entry updated
Sources
Advisory: 19527
Researcher: Soroush Dalili & Ali Abbasnejad
SecurityFocus: 54251
Misc.: packetstormsecurity.org
- Latest Entries
- EMC RSA Authentication API Encryption Key information disclosure
- Cisco Secure Access Control System Web Interface weak authentication
- Python ssl.match_hostname() denial of service
- Mozilla Firefox/Thunderbird nsContentUtils::RemoveScriptBlocker buffer overflow
- Mozilla Firefox/Thunderbird nsFrameList::FirstChild buffer overflow
- Statistics
- Archive



















