[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96125

 
 

909

 
 

78020

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

Privilege Escalation Vulnerability in Internet Information Services - MS08-005

ID: oval:org.secpod.oval:def:2654Date: (C)2011-11-02   (M)2017-10-04
Class: PATCHFamily: windows




The host is missing an important security update according to Microsoft security bulletin, MS08-005. The update is required to fix privilege escalation vulnerability. A flaw is present in Internet Information Services (IIS), which fails to handle file change notifications in the FTPRoot, NNTPFile\Root, and WWWRoot folders. Successful exploitation could allow an attacker to install programs, view, change, or delete data or create new accounts with full user rights.

Platform:
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows XP
Product:
Microsoft Internet Information Server (IIS) 5.0
Microsoft Internet Information Server (IIS) 5.1
Microsoft Internet Information Server (IIS) 6.0
Microsoft Internet Information Server (IIS) 7.0
Reference:
MS08-005
CVE-2008-0074
CVE    1
CVE-2008-0074
CPE    14
cpe:/o:microsoft:windows_2003_server::sp1:x64
cpe:/o:microsoft:windows_vista:::x86
cpe:/o:microsoft:windows_2003_server::sp2:itanium
cpe:/o:microsoft:windows_xp::sp2:x64
...
XCCDF    5
xccdf_com.secpod_benchmark_microsoft-windows-server-2003
xccdf_com.secpod_benchmark_microsoft-windows-2000
xccdf_com.secpod_benchmark_microsoft-windows-vista
xccdf_com.secpod_benchmark_microsoft-windows-xp
...

© 2013 SecPod Technologies