WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow

Published on 16 Jun 2021
Vulnerability

CVE-2017-7269 is a Buffer Overflow vulnerability in the Microsoft Internet Information Service (IIS) 6.0 web server, a part of Windows Server 2003 R2. This vulnerability is found in the ScStoragePathFromUrl function in the WebDAV service of the webserver which allows attackers to implement Remote Code Execution or cause Denial-of-Service.The exploitation is done using the long string value that begins with If: <http:// in the PROPFIND HTTP header request. PROPFIND is an HTTP method that is supported by WebDAV protocol. Web Distributed Authoring and Versioning(WebDAV) protocol is an extension of HTTP protocol that provides a framework for managing documents on web servers.

Mitigation / Precaution

  • In order to patch this vulnerability, please install the official patch Microsoft made available for supported, vulnerable instances.
  • If upgrading is not practical, consider disabling WebDAV in IIS 6.0.
Rejah Rehim
Written by
Co-founder, Director

Rejah brings more than 12 years of industry experience in Information Technology. He is a fervent security enthusiast and serves as a Project Leader at OWASP Foundation, and Commander (Hon.) at Kerala Police. He has authored two books titled “Effective Python Penetration Testing” and “Python Penetration Testing Cookbook” and is the creator of 9 Mozilla add-ons.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo