MS.IIS.FTP.NLST.DoS

Last Updated DateSep 22, 2009
Release DateSep 08, 2009
SeverityHigh
ImpactDenial of Service: Remote attackers can crash vulnerable systems.
DescriptionThis indicates an attack attempt to exploit a DoS vulnerability in Microsoft windows IIS server.

The Microsoft IIS FTP service crashes due to stack exhaustion when handling crafted NLST command. Remote attackers could exploit this to cause denial of service on the IIS server.
Affected ProductsMicrosoft Internet Information Services 5.0
Microsoft Internet Information Services 5.1
Microsoft Internet Information Services 6.0
Microsoft Internet Information Services 7.0
Recommended ActionsApply the suggested workaround from Microsoft.
http://www.microsoft.com/technet/security/advisory/975191.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2521
Reference/shttp://archives.neohapsis.com/archives/fulldisclosure/2009-09/0040.html
http://www.milw0rm.com/exploits/9587
Reference: VID-17706