CVE-2001-0506
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation"…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 68.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 68.93% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet information server · microsoft/internet information services
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=99802093532233&w=2
- http://online.securityfocus.com/archive/1/242541
- http://www.ciac.org/ciac/bulletins/l-132.shtml
- http://www.securityfocus.com/bid/3190Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6984
- http://marc.info/?l=bugtraq&m=99802093532233&w=2
- http://online.securityfocus.com/archive/1/242541
- http://www.ciac.org/ciac/bulletins/l-132.shtml
- http://www.securityfocus.com/bid/3190Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6984
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.