CVE-2006-1364
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 58.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 58.74% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- microsoft/asp.net
- Source
- cve@mitre.org
References
- http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zipBroken Link, Third Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044291.htmlThird Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044292.htmlThird Party Advisory
- http://securitytracker.com/id?1015825Third Party Advisory, VDB Entry
- http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.htmlExploit, Third Party Advisory
- http://www.securityfocus.com/archive/1/428622/100/0/threaded
- http://www.securityfocus.com/bid/17188Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25392Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/1601Exploit, Third Party Advisory, VDB Entry
- http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zipBroken Link, Third Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044291.htmlThird Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044292.htmlThird Party Advisory
- http://securitytracker.com/id?1015825Third Party Advisory, VDB Entry
- http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.htmlExploit, Third Party Advisory
- http://www.securityfocus.com/archive/1/428622/100/0/threaded
- http://www.securityfocus.com/bid/17188Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25392Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/1601Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.