CVE-2017-7269
KEVHIGH 10.0EPSS 99.8%
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 99.82% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03
- Nuclei
- critical · CWE-119
- Published
- 2017-03-27
- Updated
- 2025-10-21
Proof-of-concept exploits (30)
- Al1ex/CVE-2017-726911★ · 2018-04-28
- Cappricio-Securities/CVE-2017-72691★ · 2024-06-24
- N3rdyN3xus/CVE-2017-72695★ · 2021-07-16
- NyxByt3/CVE-2017-72695★ · 2021-07-16
- Sp3c73rSh4d0w/CVE-2017-72695★ · 2021-07-16
- ThanHuuTuan/CVE-2017-72690★ · 2017-04-04
- VanishedPeople/CVE-2017-72690★ · 2024-09-05
- admintony/CollectionOfExp3★ · 2018-03-25
- c0d3cr4f73r/CVE-2017-72695★ · 2021-07-16
- caicai1355/CVE-2017-7269-exploit1★ · 2017-03-29
- danigargu/explodingcan268★ · 2018-01-04
- denchief1/CVE-2017-72690★ · 2022-08-29
- eliuha/webdav_exploit22★ · 2017-03-29
- g0rx/iis6-exploit-2017-CVE-2017-726992★ · 2023-02-04
- geniuszly/CVE-2017-72694★ · 2024-10-07
- geniuszlyy/CVE-2017-72694★ · 2024-10-07
- h3x0v3rl0rd/CVE-2017-72695★ · 2021-07-16
- h3xcr4ck3r/CVE-2017-72695★ · 2021-07-16
- homjxi0e/cve-2017-72690★ · 2017-04-13
- k4u5h41/CVE-2017-72695★ · 2021-07-16
- lcatro/CVE-2017-7269-Echo-PoC89★ · 2018-10-27
- n3rdh4x0r/CVE-2017-72695★ · 2021-07-16
- slimpagey/IIS_6.0_WebDAV_Ruby5★ · 2017-04-06
- vysecurity/IIS_exploit3★ · 2017-03-27
- whiteHat001/cve-2017-7269picture0★ · 2017-03-30
- xdx57/WebDav_Exploiter0★ · 2022-04-16
- zcgonvh/cve-2017-7269135★ · 2017-03-30
- zcgonvh/cve-2017-7269-tool88★ · 2017-05-16
- Killian0713/Assignement_3-CVE-2017-7269
- Mr-xn/Penetration_Testing_POC