CVE-2017-7269CISA KEV
Microsoft Windows Server Buffer Overflow Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
- Product
- Internet Information Services (IIS)
- Added to KEV
- 3 Nov 2021
- Federal remediation due
- 3 May 2022
- Known ransomware use
- Not reported