Unpatched Microsoft IIS 6 web server flaw affects millions of websites

Edward Hudson By: Edward Hudson
2 minute read

Home » News » Unpatched Microsoft IIS 6 web server flaw affects millions of websites

Microsoft might not be able to fix a zero-day vulnerability in an older version of its Internet Information Services web server that attackers targeted July and August of last year. The exploit lets attackers execute malicious code on Windows servers that run IIS 6.0 while user privileges run the application. A proof-of-concept exploit for the vulnerability in IIS 6.0 is now available to view on GitHub and while IIS 6.0 is no longer supported, it remains widely used even today. Support for this version of IIS stopped in July of last year along with support for the Windows Server 2003, its parent product.

The news raises concern among security professionals as web server surveys indicate that IIS 6.0 is still being used by millions of public websites. Also, it is possible that a large number of companies could still be running web applications on Windows Server 2003 and IIS 6.0 inside their organization. Attackers could, therefore, use the flaw to perform lateral movements if they gain access to corporate networks.

Prior to its publication on GitHub, only a few attackers were aware of the vulnerability — until recently. Now, there is evidence that many attackers now have access to the unpatched flaw. Security vendor Trend Micro offers the following explanation for the vulnerability:

A remote attacker could exploit this vulnerability in the IIS WebDAV Component with a crafted request using PROPFIND  method. Successful exploitation could result in denial of service condition or  arbitrary code execution in the context of the user running the application. According to the researchers who found this flaw, this vulnerability was exploited in the wild in July or August 2016. It was disclosed to the public on March 27. Other threat actors are now in the stages of creating malicious code based on the original proof-of-concept (PoC) code.

Trend Micro noted that Web Distributed Authoring and Versioning (WebDAV) is an extension of the standard Hypertext Transfer Protocol that lets users create, change and move documents on a server. The extension provides support for several request methods such as PROPFIND. The company recommends disabling the WebDAV service on IIS 6.0 installations to help mitigate the issue.

Discussions

Next up

Graph Math Equations are coming to Windows 10 Calculator

Zille Huma avatar. By: Zille Huma
2 minute read

A new feature to the Windows 10 Calculator app is currently under development. Recent reports suggest that Microsoft is adding a graphing mode to its […]

Continue Reading

File Explorer will get new Fluent Design elements in 2020

Irfa Batool avatar. By: Irfa Batool
2 minute read

Folks, we’ve got some good news for you: File Explorer will soon be updated with Fluent Design elements. The new Fire Explorer should hit the […]

Continue Reading

Here’s how to fix Something went wrong QuickBooks Online error

John Waibochi avatar. By: John Waibochi
4 minute read

When working in QuickBooks, you may get the Something went wrong error. This can happen, for instance, when you’re trying to drill down your customized […]

Continue Reading