MS11-004: Vulnerability in Internet Information Services (IIS) FTP Service Could Allow Remote Code Execution (2489256) (uncredentialed check)

critical Nessus Plugin ID 51956

Synopsis

The FTP service running on the remote host has a memory corruption vulnerability.

Description

The IIS FTP service running on the remote host has a heap-based buffer overflow vulnerability. The 'TELNET_STREAM_CONTEXT::OnSendData' function fails to properly sanitize user input, resulting in a buffer overflow.

An unauthenticated, remote attacker can exploit this to execute arbitrary code.

Solution

Microsoft has released a set of patches for Windows Vista, 2008, 2008 R2, and 7.

See Also

http://www.nessus.org/u?f1d70f2a

Plugin Details

Severity: Critical

ID: 51956

File Name: iis_ftp7_heap_overflow.nasl

Version: 1.20

Type: remote

Agent: windows

Family: Windows

Published: 2/11/2011

Updated: 1/16/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2010-3972

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:iis

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/8/2011

Vulnerability Publication Date: 12/21/2010

Exploitable With

Core Impact

Reference Information

CVE: CVE-2010-3972

BID: 45542

MSFT: MS11-004

MSKB: 2489256