CVE-2009-1536
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 51.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 51.32% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/.net framework · microsoft/windows server 2008 · microsoft/windows vista
- Source
- secure@microsoft.com
References
- http://blogs.technet.com/srd/archive/2009/08/11/ms09-035-asp-net-denial-of-service-vulnerability.aspxVendor Advisory
- http://osvdb.org/56905Broken Link
- http://secunia.com/advisories/36127Third Party Advisory
- http://www.securityfocus.com/bid/35985Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022715Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-223A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2009/2231Permissions Required, Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-036
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6393Third Party Advisory
- http://blogs.technet.com/srd/archive/2009/08/11/ms09-035-asp-net-denial-of-service-vulnerability.aspxVendor Advisory
- http://osvdb.org/56905Broken Link
- http://secunia.com/advisories/36127Third Party Advisory
- http://www.securityfocus.com/bid/35985Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022715Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-223A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2009/2231Permissions Required, Third Party Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-036
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6393Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.