| Microsoft Windows Knowledge Base Article 970483 update is not installed (WinMs09kb970483Update) |
|---|
| Vuln ID: | 50768 | |
|---|---|---|
| Risk Level: | High |
WinMs09kb970483Update |
| Platforms: | Microsoft IIS: 6.0, Microsoft Windows 2000: SP4, Microsoft Windows XP: SP2 Professional, Microsoft Windows XP: SP2, Microsoft Windows Server 2003: SP2, Microsoft Windows Server 2003: SP2 Itanium, Microsoft Windows Server 2003: SP2 x64, Microsoft Windows XP: SP2 x64 Professional, Microsoft Internet Information Server: 5.0, Microsoft Internet Information Server: 5.1, Microsoft Windows XP: SP3, Microsoft Windows XP: SP3 Professional | |
| Description: | Microsoft Knowledge Base Article 970483 is not installed, which could allow a remote attacker to exploit the following vulnerabilities: Microsoft Internet Information Services (IIS) could allow a remote attacker to bypass security restrictions, caused by the improper handling of WebDAV requests for directories requiring authentication. By sending a specially-crafted HTTP request to a WebDAV-enabled IIS server, a remote attacker could exploit this vulnerability to bypass security restrictions and download protected files. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS09-020. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS09-020 IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2009-1122 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |