CVE-2009-2521

Description

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka IIS FTP Service DoS Vulnerability.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C
EPSS Score
Exploitation Probability
60.775

Associated Vulnerability

VulnerabilityOS Platform
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2003 (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista (KB975254) x86 based systemsWindows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista (KB975254) x86 based systems for SP1Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista (KB975254) x86 based systems for SP2Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 (KB975254) x86 based systemsWindows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 (KB975254) x86 based systems for SP2Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows XP x64 Edition (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2003 x64 Edition (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista for x64-based Systems (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista for x64-based Systems (KB975254) for SP1Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista for x64-based Systems (KB975254) for SP2Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 x64 Edition (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 x64 Edition (KB975254) for SP2Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-7608Security Update for Windows Server 2008 (KB975254)
PATCH-7609Security Update for Windows Server 2008 (KB975254)
PATCH-7615Security Update for Windows Server 2008 x64 Edition (KB975254)
PATCH-7616Security Update for Windows Server 2008 x64 Edition (KB975254)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234