CVE-2017-7269 — Microsoft Windows Server Buffer Overflow Vulnerability
2021-11-03 • CISA Known Exploited Vulnerability
[event] Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Microsoft |
| Product | Internet Information Services (IIS) |
| CWE | CWE-119 |
| CVE ID | CVE-2017-7269 |
| Date Added | 2021-11-03 |
| Due Date | 2022-05-03 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-05-03