// For flags

CVE-2009-1535

Microsoft IIS 6.0 - WebDAV Remote Authentication Bypass

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.

La extensión de WebDAV en Microsoft Internet Information Services (IIS) v5.1 y v6.0 permite a atacantes remotos eludir los mecanismos de protección basados en URL, y listar carpetas o leer, crear o modificar archivos, a través de un %c0%af (Unicode / carácter) en una posición arbitraria en la URL, como se ha demostrado mediante la inserción de %c0%af en la ruta inicial de componente "/protected/" para evitar la protección por contraseña en la carpeta protected\ , alias "IIS v5.1 y v6.0 Vulnerabilidad de evasión de autenticación WebDAV".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-05-05 CVE Reserved
  • 2009-05-15 First Exploit
  • 2009-06-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-03 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
5.1
Search vendor "Microsoft" for product "Internet Information Services" and version "5.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
-sp2, professional
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
5.1
Search vendor "Microsoft" for product "Internet Information Services" and version "5.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
-sp3, professional
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
6.0
Search vendor "Microsoft" for product "Internet Information Services" and version "6.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Server 2003
Search vendor "Microsoft" for product "Windows Server 2003"
-sp2
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
6.0
Search vendor "Microsoft" for product "Internet Information Services" and version "6.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Server 2003
Search vendor "Microsoft" for product "Windows Server 2003"
-sp2, itanium
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
6.0
Search vendor "Microsoft" for product "Internet Information Services" and version "6.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Server 2003
Search vendor "Microsoft" for product "Windows Server 2003"
-sp2, x64
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
6.0
Search vendor "Microsoft" for product "Internet Information Services" and version "6.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Xp
Search vendor "Microsoft" for product "Windows Xp"
-sp2, professional, x64
Safe