Microsoft Media Services ISAPI nsiislog.dll Multiple Overflows

critical Nessus Plugin ID 11664

Language:

Synopsis

Arbitrary code can be executed on the remote host.

Description

Some versions of IIS shipped with a default file, nsiislog.dll, within the /scripts directory. Nessus has determined that the remote host has the file installed.

The NSIISLOG.dll CGI may allow an attacker to execute arbitrary commands on this host, through a buffer overflow.

Solution

Microsoft has released a patch for Windows 2000.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2003/ms03-022

Plugin Details

Severity: Critical

ID: 11664

File Name: nsiislog_dll.nasl

Version: 1.39

Type: remote

Family: Web Servers

Published: 5/28/2003

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.5

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/28/2003

Exploitable With

CANVAS (CANVAS)

Metasploit (MS03-022 Microsoft IIS ISAPI nsiislog.dll ISAPI POST Overflow)

Reference Information

CVE: CVE-2003-0227, CVE-2003-0349

BID: 7727, 8035

MSFT: MS03-022

MSKB: 822343