Vulnerability Name: | CCN-466 | ||||||
Published: | 1997-06-01 | ||||||
Updated: | 1997-06-01 | ||||||
Summary: | A vulnerability in some ISAPI scripts could execute the RevertToSelf function on Microsoft IIS. Once the RevertToSelf function is executed, the program reverts its authority to the account SYSTEM, which provides the program extended powers of the SYSTEM account. This could allow the program to execute such things as system calls. | ||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: Security Bugware Web site Reverting the "IUSR-MACHINENAME" Account Source: XF Type: UNKNOWN isapi(466) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |