int(4696)

Vulnerability Bulletins


Aumento de privilegios en Microsoft ISS

Vulnerability classification

Property Value
Confidence level Oficial
Impact Aumento de privilegios
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft ISS 5 y 6

Description

Se ha descubierto una vulnerabilidad en Microsoft ISS 5 y 6. La vulnerabilidad reside en un error en la extensión WebDAV.

Un atacante remoto podría saltar la autenticación y crear o modificar ficheros mediante una petición HTTP especialmente diseñada.

Solution



Actualización de software

Microsoft (MS09-020)
Internet Information Services
Microsoft Windows 2000 Service Pack 4 / patch Windows2000-KB970483-x86-ENU
Windows XP (32-bit) / patch Windowsxp-KB970483-x86-enu
Windows XP Professional (x64) / patch Windowsserver2003.Windows XP-KB970483-x64-ENU
Windows Server 2003 (32-bit) / patch WindowsServer2003-KB970483-x86-enu
Windows Server 2003 (Itanium) / patch WindowsServer2003-KB970483-ia64-enu
Windows Server 2003 (x64) / patch WindowsServer2003.WindowsXP-KB970483-x64-enu

Standar resources

Property Value
CVE CVE-2009-1122
BID

Other resources

Microsoft Security Bulletin (MS09-020)
http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2009-06-15