HomeSecurityIIS Windows: RCE vulnerability via HTTP requests

IIS Windows: RCE vulnerability via HTTP requests

IIS Windows: RCE vulnerability via HTTP requests

IIS Windows: RCE vulnerability via HTTP requests

A new vulnerability found in the HTTP stack of Windows systems allows attackers to remotely execute code.

This RCE (Remote Code Execution) vulnerability occurs when HTTP.sys attempts to parse specially crafted HTTP requests. An attacker who successfully exploits the vulnerability could execute code from the SYSTEM account of  IIS Windows.

Microsoft provides more information in MS15-034. A patch has not yet been released, and as a temporary workaround, disabling kernel caching for IIS is recommended.

Meanwhile, code that remotely checks for the presence of the vulnerability has already appeared. More about the check is provided in a blog post by Mattias Geniar.

 

Source: deltahacker.gr/

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS