HTTP: Microsoft IIS Server Crafted ASP Page Buffer Overflow

This signature detects attempts to exploit a known vulnerability in Microsoft IIS Server Crafted ASP Page. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Microsoft Internet Information Server (IIS) is prone to a remote code-execution vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. To exploit this issue, attackers must be able to place and execute malicious ASP pages on computers running the affected ASP server software. This may be an issue in shared-hosting environments. This issue allows remote attackers to execute arbitrary machine code in the context of the affected webserver software.

Affected Products

Microsoft windows_xp_media_center_edition

Short Name
HTTP:IIS:ASP-PAGE-BOF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ASP Buffer CVE-2006-0026 Crafted IIS Microsoft Overflow Page Server bid:18858
Release Date
07/11/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Microsoft

CVSS Score

6.5

Found a potential security threat?