Microsoft IIS 5 .printer ISAPI Filter Enabled

info Nessus Plugin ID 10661
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote web server supports Internet Printing Protocol.

Description

IIS 5 has support for the Internet Printing Protocol(IPP), which is enabled in a default install. The protocol is implemented in IIS5 as an ISAPI extension. At least one security problem (a buffer overflow) has been found with that extension in the past, so we recommend you disable it if you do not use this functionality.

Solution

To unmap the .printer extension :

1. Open Internet Services Manager.
2. Right-click the Web server choose Properties from the context menu.
3. Master Properties 4. Select WWW Service -> Edit -> HomeDirectory -> Configuration

and remove the reference to .printer from the list.

Plugin Details

Severity: Info

ID: 10661

File Name: iis5_isapi_printer.nasl

Version: 1.37

Type: remote

Family: Web Servers

Published: 5/3/2001

Updated: 6/12/2020

Dependencies: find_service1.nasl, no404.nasl, http_version.nasl, www_fingerprinting_hmap.nasl

Vulnerability Information

CPE: cpe:/a:microsoft:iis