Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

FTP:MS-FTP:MSFTPSVC-EXEC

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

FTP

Keywords

Microsoft IIS FTP Server Code Execution

Release Date

2009/10/13

Update Number

1522

Supported Platforms

idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

FTP: Microsoft IIS FTP Server Code Execution


This signature detects attempts to exploit a known vulnerability against the Microsoft IIS FTP server. A successful attack can lead to arbitrary code execution.

Extended Description

Microsoft IIS is prone to a remote stack-based buffer-overflow vulnerability affecting the application's FTP server. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. This issue affects the following: IIS 5.0 IIS 5.1 IIS 6.0 (denial of service only) IIS 7.0 (denial of service only) Note that Microsoft IIS 7.0 with FTP Service 7.5 is not affected. Other versions may also be affected. NOTE: This issue cannot be exploited to execute arbitrary code on IIS 6.0 or 7.0. NOTE (September 1, 2009): This issue can be exploited to execute arbitrary code with SYSTEM-level privileges on IIS 5.0. UPDATE (September 8, 2009); This issue may be related to a vulnerability reported in 1999 affecting IIS 3 and IIS 4. We will update this BID as more details emerge.

Affected Products

  • Microsoft IIS 5.0
  • Microsoft IIS 5.1
  • Microsoft IIS 6.0

References

  • BugTraq: 36189
  • CVE: CVE-2009-3023
  • URL: http://www.microsoft.com/technet/security/advisory/975191.mspx

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out