HTTP: Microsoft IIS Request Header Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Microsoft IIS. Successful exploitation would allow an attacker to inject and execute arbitrary code

Extended Description

Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."

Affected Products

Microsoft internet_information_services

References

CVE: CVE-2017-7529

Short Name
HTTP:IIS:REQ-HDR-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2010-2730 CVE-2013-3075 CVE-2017-7529 Header IIS Microsoft Overflow Request
Release Date
02/11/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

10.0

5.0

Found a potential security threat?