{"id":"CVE-2017-7269","aliases":[],"url":"https://o3.security/vulnerability/CVE-2017-7269","summary":"Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to…","details":"Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with \"If: <http://\" in a PROPFIND request, as exploited in the wild in July or August 2016.","published":"2017-03-27T01:55:00.000Z","modified":"2025-10-21T23:55:43.335Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.99823,"percentile":0.99958,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2021-11-03","dueDate":"2022-05-03","knownRansomwareCampaignUse":false},"exploitsKnown":41,"affectedPackages":[],"fix":{"url":"https://github.com/rapid7/metasploit-framework/pull/8162","label":"rapid7/metasploit-framework#8162"},"references":[{"type":"EXPLOIT","url":"https://www.exploit-db.com/exploits/41992/"},{"type":"WEB","url":"http://www.securityfocus.com/bid/97127"},{"type":"WEB","url":"https://medium.com/%40iraklis/number-of-internet-facing-vulnerable-iis-6-0-to-cve-2017-7269-8bd153ef5812"},{"type":"WEB","url":"https://github.com/rapid7/metasploit-framework/pull/8162"},{"type":"WEB","url":"https://github.com/danigargu/explodingcan"},{"type":"WEB","url":"http://www.securitytracker.com/id/1038168"},{"type":"EXPLOIT","url":"https://www.exploit-db.com/exploits/41738/"},{"type":"WEB","url":"https://support.microsoft.com/en-us/help/3197835/description-of-the-security-update-for-windows-xp-and-windows-server"},{"type":"WEB","url":"https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html"},{"type":"WEB","url":"https://github.com/edwardz246003/IIS_exploit"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-7269"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:55:43.335Z"}}