CVE-2009-3023
HIGH 9.0EPSS 90.9%
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
- CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 90.91% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2009-08-31
- Updated
- 2024-08-07
Proof-of-concept exploits (2)
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16740
- https://www.exploit-db.com/exploits/9559
- https://www.exploit-db.com/exploits/9541