CVE-2017-7269
Microsoft Windows Server Buffer Overflow Vulnerability
9.8
CVSS 3.1
99.8 %
EPSS (current)
2021-11-03
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / Internet Information Services (IIS)
Published: 2017-03-27 · Due (CISA): 2022-05-03
CWE: CWE-120 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2017/CVE-2017-7269.yaml | Windows Server 2003 & IIS 6.0 - Remote Code Execution | – |
| metasploit | exploit/windows/iis/iis_webdav_scstoragepathfromurl | exploit/windows/iis/iis_webdav_scstoragepathfromurl | 2017-03-26 |
| exploitdb | 41738 | Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow | 2017-03-27 |
| exploitdb | 41992 | Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit) | 2017-05-11 |
References only — no downloads or instructions.