CVE-2017-7269

critical

Description

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

References

https://github.com/dopaminauta/university-security-audit

https://github.com/Admin2099/Penetration-Testing-Assessment-23-04-2026

https://github.com/Silence-Cy/ModuScan

https://github.com/Ernest-Kosmatko/Netrecon

https://github.com/THU-HJY/CVE-Honeypot

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/Deloney-code/AI-Powered-Red-Team-Automation

https://github.com/OmarSuarezDoro/CVE-2017-7269

https://github.com/0xget/cve-2001-1473

https://github.com/denchief1/CVE-2017-7269

https://github.com/denchief1/CVE-2017-7269_Python3

https://github.com/mirrorblack/CVE-2017-7269

https://github.com/zcgonvh/cve-2017-7269-tool

https://github.com/xiaovpn/CVE-2017-7269

https://github.com/slimpagey/IIS_6.0_WebDAV_Ruby

https://github.com/g0rx/iis6-exploit-2017-CVE-2017-7269

https://github.com/lcatro/CVE-2017-7269-Echo-PoC

https://github.com/eliuha/webdav_exploit

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-7269

https://support.microsoft.com/en-us/help/3197835/description-of-the-security-update-for-windows-xp-and-windows-server

https://medium.com/%40iraklis/number-of-internet-facing-vulnerable-iis-6-0-to-cve-2017-7269-8bd153ef5812

https://github.com/rapid7/metasploit-framework/pull/8162

https://github.com/edwardz246003/IIS_exploit

https://github.com/danigargu/explodingcan

https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html

http://www.securitytracker.com/id/1038168

http://www.securityfocus.com/bid/97127

Details

Source: Mitre, NVD

Published: 2017-03-27

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99823