CVE-2009-3023

Description

Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka IIS FTP Service RCE and DoS Vulnerability.

Risk Information

Base Score
9.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Exploitation Probability
77.219

Associated Vulnerability

VulnerabilityOS Platform
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2003 (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista (KB975254) x86 based systemsWindows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista (KB975254) x86 based systems for SP1Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista (KB975254) x86 based systems for SP2Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 (KB975254) x86 based systemsWindows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 (KB975254) x86 based systems for SP2Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows XP x64 Edition (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2003 x64 Edition (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista for x64-based Systems (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista for x64-based Systems (KB975254) for SP1Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Vista for x64-based Systems (KB975254) for SP2Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 x64 Edition (KB975254)Windows
ms09-053: vulnerabilities in ftp service for internet information services could allow remote code execution for Windows Server 2008 x64 Edition (KB975254) for SP2Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-7608Security Update for Windows Server 2008 (KB975254)
PATCH-7609Security Update for Windows Server 2008 (KB975254)
PATCH-7615Security Update for Windows Server 2008 x64 Edition (KB975254)
PATCH-7616Security Update for Windows Server 2008 x64 Edition (KB975254)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234