Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rchr-fxr5-m4xq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.

EPSS

Процентиль: 85%
0.02534
Низкий

Связанные уязвимости

CVSS3: 9.9
nvd
почти 6 лет назад

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.

CVSS3: 7.5
msrc
почти 6 лет назад

Microsoft IIS Server Elevation of Privilege Vulnerability

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость пакета сетевых служб Microsoft Internet Information Services операционных систем Windows, связанная с ошибками обработки объектов в памяти, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 85%
0.02534
Низкий