{
    "id": "CVE-2017-7269",
    "published": "2017-03-27 02:59:00",
    "last_modified": "2026-06-17 01:23:58",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-120",
    "description": "Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with \"If: <http://\" in a PROPFIND request, as exploited in the wild in July or August 2016.",
    "epss_score": "0.99823",
    "epss_percentile": "0.99959",
    "kev": 1,
    "kev_due": "2022-05-03",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:21:09",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2022-05-03."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "internet_information_services"
        },
        {
            "vendor": "microsoft",
            "product": "windows_server_2003"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2017-7269",
        "date_added": "2021-11-03",
        "due_date": "2022-05-03",
        "vendor": "Microsoft",
        "product": "Internet Information Services (IIS)",
        "name": "Microsoft Windows Server Buffer Overflow Vulnerability",
        "ransomware": 0
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "41992",
            "title": "Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)",
            "date": "2017-05-11",
            "url": "https://www.exploit-db.com/exploits/41992"
        },
        {
            "source": "exploit-db",
            "ref_id": "41738",
            "title": "Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow",
            "date": "2017-03-27",
            "url": "https://www.exploit-db.com/exploits/41738"
        }
    ],
    "refs_list": [
        "http://www.securityfocus.com/bid/97127",
        "http://www.securitytracker.com/id/1038168",
        "https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html",
        "https://github.com/danigargu/explodingcan",
        "https://github.com/edwardz246003/IIS_exploit",
        "https://github.com/rapid7/metasploit-framework/pull/8162",
        "https://medium.com/%40iraklis/number-of-internet-facing-vulnerable-iis-6-0-to-cve-2017-7269-8bd153ef5812",
        "https://support.microsoft.com/en-us/help/3197835/description-of-the-security-update-for-windows-xp-and-windows-server",
        "https://www.exploit-db.com/exploits/41738/",
        "https://www.exploit-db.com/exploits/41992/",
        "http://www.securityfocus.com/bid/97127",
        "http://www.securitytracker.com/id/1038168",
        "https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html",
        "https://github.com/danigargu/explodingcan",
        "https://github.com/edwardz246003/IIS_exploit",
        "https://github.com/rapid7/metasploit-framework/pull/8162",
        "https://medium.com/%40iraklis/number-of-internet-facing-vulnerable-iis-6-0-to-cve-2017-7269-8bd153ef5812",
        "https://support.microsoft.com/en-us/help/3197835/description-of-the-security-update-for-windows-xp-and-windows-server",
        "https://www.exploit-db.com/exploits/41738/",
        "https://www.exploit-db.com/exploits/41992/",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-7269"
    ]
}