CVE-2007-2815
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 73.35% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/internet information services
- Source
- cve@mitre.org
References
- http://osvdb.org/41091
- http://securityreason.com/securityalert/2725
- http://support.microsoft.com/kb/328832
- http://www.securityfocus.com/archive/1/469238/100/0/threaded
- http://www.securityfocus.com/bid/24105
- http://osvdb.org/41091
- http://securityreason.com/securityalert/2725
- http://support.microsoft.com/kb/328832
- http://www.securityfocus.com/archive/1/469238/100/0/threaded
- http://www.securityfocus.com/bid/24105
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.