Vulnerability Note VU#787932
Microsoft IIS WebDAV Remote Authentication Bypass
Overview
A vulnerability exists in the way Microsoft Internet Information Server (IIS) handles unicode tokens that may allow authentication bypass.
Description
Web-based Distributed Authoring and Versioning (WebDAV) is a set of HTTP extensions that allow collaborative management and editing of files collected on remote servers. The way that Microsoft IIS's implementation of WebDAV handles unicode tokens may allow authentication bypass. According to Nikolaos Rangos: The specific flaw exists within the WebDAV functionality of IIS 6.0. The Web Server fails to properly handle unicode tokens when parsing the URI and sending back data. |
Impact
A remote attacker may be able to bypass the access restrictions and list, download, upload and modify protected files. |
Solution
We are currently unaware of a practical solution to this problem. Please consider the following workarounds: |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 19 May 2009 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://seclists.org/fulldisclosure/2009/May/0134.html
- http://blog.zoller.lu/2009/05/iis-6-webdac-auth-bypass-and-data.html
- http://milw0rm.com/exploits/8704
- http://www.microsoft.com/technet/security/advisory/971492.mspx
Credit
This vulnerability was publicly disclosed by Nikolaos Rangos.
This document was written by Chris Taschner.
Other Information
- CVE IDs: CVE-2009-1535
- Date Public: 12 Mar 2009
- Date First Published: 19 May 2009
- Date Last Updated: 20 May 2009
- Document Revision: 17
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.