Vulnerability Name: | CVE-2000-0770 (CCN-5071) | ||||||||
Assigned: | 2000-08-10 | ||||||||
Published: | 2000-08-10 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability. | ||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2000-0770 Source: CCN Type: Microsoft Security Bulletin MS00-057 FAQ Microsoft Security Bulletin (MS00-057): Frequently Asked Questions Source: CCN Type: Microsoft Security Bulletin MS00-057 Patch Available for 'File Permission Canonicalization' Vulnerability Source: CCN Type: Microsoft Security Bulletin MS01-041 Malformed RPC Request Can Cause Service Failure Source: CCN Type: Microsoft Security Bulletin MS02-001 Trusting Domains Do Not Verify Domain Membership of SIDs in Authorization Data Source: CCN Type: Microsoft Security Bulletin MS02-018 Cumulative Patch for Internet Information Services (Q319733) Source: CCN Type: Microsoft Security Bulletin MS02-062 Cumulative Patch for Internet Information Service (Q327696) Source: CCN Type: Microsoft Security Bulletin MS03-018 Cumulative Patch for Internet Information Service (811114) Source: CCN Type: OSVDB ID: 1504 Microsoft IIS File Permission Canonicalization Bypass Source: BID Type: Patch, Vendor Advisory 1565 Source: CCN Type: BID-1565 Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability Source: MS Type: UNKNOWN MS00-057 Source: XF Type: UNKNOWN iis-incorrect-permissions(5071) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |