Summary
Microsoft IIS FTPd NLST stack overflow
The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the write access necessary to trigger it without authentication.
On the following platforms, we recommend you mitigate in the described manner:
Microsoft IIS 5.x
Microsoft IIS 6.x
We recommend you mitigate in the following manner:
Filter inbound traffic to 21/tcp to only known management hosts Consider removing directories writable by 'anonymous'
Solution
We are not aware of a vendor approved solution at the current time.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-3023 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- pyftpdlib FTP Server Multiple Vulnerabilities
- Trellian FTP 'PASV' Response Buffer Overflow Vulnerability
- Easy FTP Server POST Auth 'MKD' Command Buffer Overflow Vulnerability
- ActFax FTP Server Post Auth 'RETR' Command Denial of Service Vulnerability
- XM Easy Personal FTP Server 'NLST' Command Remote Denial of Service Vulnerability