Skip to content
COOEY

EXPOSURES › CVE-2017-7269

CVE-2017-7269

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-7269 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A buffer overflow in Microsoft IIS 6.0 on Windows Server 2003 R2 allowed remote attackers to execute code via a malformed PROPFIND request.

This unpatched vulnerability in legacy IIS 6.0 enabled remote code execution, a critical risk for organizations still running end-of-life systems. DIBs must ensure no legacy IIS 6.0 remains unpatched or unmonitored, as it was actively exploited in the wild and linked to ransomware campaigns. Immediate remediation involves patching or decommissioning affected systems.

Shame score — Microsoft failed to patch a known, actively exploited vulnerability in a widely deployed legacy product, enabling remote code execution and linking to ransomware attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Widespread condemnation due to exploitation and age of vulnerability.
NVD ↗ severe-fallout -0.90
Highlights the age and potential severity of the issue.
"You are viewing this page in an unauthorized frame window."
cooey ↗ severe-fallout -0.70
Neutral description of the vulnerability.
"Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code."
www.cvefind.com ↗ severe-fallout -0.60
Implies a significant vendor oversight.
"TOP 100 Vendors with CVE"
app.opencve.io ↗ severe-fallout -0.50
Neutral listing, no specific commentary.
"CVEs in KEV"
classactionu.org ↗ severe-fallout +0.00
Neutral listing, no specific commentary.
xposedornot.com ↗ severe-fallout +0.00
Neutral listing, no specific commentary.
cyberinsider.com ↗ severe-fallout +0.00
Neutral listing, no specific commentary.
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized