
Vulnerability ID: CVE-2017-7269
Discoverers: Zhiniang Peng and Chen Wu (Information Security Laboratory, School of Computer Science and Engineering, South China University of Technology)
Description: IIS 6.0 does not enable WebDAV by default. Once WebDAV support is enabled, servers running IIS 6.0 may be threatened by this vulnerability.
Type: Buffer Overflow
Severity: High
Affected Products: Microsoft Windows Server 2003 R2 with IIS 6.0 and WebDAV service enabled
Trigger Function: ScStoragePathFromUr function
Additional Information: The ScStoragePathFromUr function is called twice
Vulnerability Details: A buffer overflow vulnerability exists in the ScStorgPathFromUrl function of the WebDAV service in IIS 6.0 on Windows Server 2003 R2. A remote attacker can execute arbitrary code by sending a PROPFIND request with a long header starting with "if:<http://". This vulnerability has been exploited since July 2016.
The exploit for this vulnerability provided here needs to be used in conjunction with Metasploit in Kali Linux!