HTTP: Microsoft IIS Request Header FastCGI Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Microsoft Windows HTTP Services. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the HTTP services.

Extended Description

Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."

Affected Products

Microsoft internet_information_services

References

CVE: CVE-2010-2730

Short Name
HTTP:OVERFLOW:IIS-FASTCGI-OF
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Buffer CVE-2010-2730 FastCGI Header IIS Microsoft Overflow Request
Release Date
07/25/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?