int(4666)

Vulnerability Bulletins


Aumento de privilegios en Microsoft ISS

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Internet Information Services <= 6

Description

Se ha descubierto una vulnerabilidad en Microsoft ISS 5 y 6. La vulnerabilidad reside en un error en el manejo de las peticiones HTTP en la extensión WebDav.

Un atacante remoto podría saltar la autenticación mediante una petición HTTP especialmente diseñada.

Solution



Actualización de software

Microsoft (MS09-020)
Internet Information Services
Microsoft Windows 2000 Service Pack 4 / patch Windows2000-KB970483-x86-ENU
Windows XP (32-bit) / patch Windowsxp-KB970483-x86-enu
Windows XP Professional (x64) / patch Windowsserver2003.Windows XP-KB970483-x64-ENU
Windows Server 2003 (32-bit) / patch WindowsServer2003-KB970483-x86-enu
Windows Server 2003 (Itanium) / patch WindowsServer2003-KB970483-ia64-enu
Windows Server 2003 (x64) / patch WindowsServer2003.WindowsXP-KB970483-x64-enu

Standar resources

Property Value
CVE CVE-2009-1535
BID

Other resources

Microsoft Security Advisory (971492)
http://www.microsoft.com/technet/security/advisory/971492.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2009-05-19
1.1 Aviso emitido por Microsoft (MS09-020) 2009-06-15