CVE-2001-0507
published 2001-09-20CVE-2001-0507: IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System…
PriorityP270high7.2CVSS 2.0
AVLACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
4.45%
90.3th percentile
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_information_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
filenameIISCrack.dll
filenamehttpodbc.dll
- →Monitor for creation or modification of httpodbc.dll in IIS 5.0 directories, which may indicate DLL side-loading abuse via CVE-2001-0507.
- →Detect presence of IISCrack.dll on disk, particularly in IIS-related paths, as it is used by FIN13 for DLL side-loading privilege escalation.
- →Alert on any local user with write permissions to IIS 5.0 in-process directories executing code at SYSTEM privilege level, consistent with the vulnerability's exploitation path. ↗
- ·CVE-2001-0507 only affects IIS 5.0 and relies on relative path resolution for in-process system files; exploitation requires a local user with write permissions to the relevant directory. ↗
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p9gc-mhgg-w6vh: IIS 5
ghsa_unreviewed·2022-04-30
CVE-2001-0507 [HIGH] GHSA-p9gc-mhgg-w6vh: IIS 5
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
VulnCheck
Microsoft IIS 5.0 System file listing Privilege Escalation
vulncheck·2001·CVSS 7.2
CVE-2001-0507 [HIGH] Microsoft IIS 5.0 System file listing Privilege Escalation
Microsoft IIS 5.0 System file listing Privilege Escalation
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
Affected: Microsoft Microsoft Internet Information Server (IIS)
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://f.hubspotusercontent30.net/hubfs/8776530/Sygnia-%20Elephant%20Beetle_Jan2022.pdf
No detection rules found.
Threat Intel
FIN13 (FIN13, Elephant Beetle)
threat_intel·CVSS 10.0
[CRITICAL] FIN13 (FIN13, Elephant Beetle)
# Threat Actor Profile: FIN13
ATT&CK ID: G1016
Also known as: FIN13, Elephant Beetle
## Overview
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)
## Techniques (TTPs)
### Reconnaissance
- T1589 Gather Victim Identity Information
Usage: FIN13 has researched employees to target for social engineering attacks.(Citation: Mandiant FIN13 Aug 2022)
- T1590.004 Network Topology
Usage: FIN13 has searched for infrastructure that can provide remote access to an environment for targ
http://online.securityfocus.com/archive/1/205069http://www.ciac.org/ciac/bulletins/l-132.shtmlhttp://www.osvdb.org/5607https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044https://exchange.xforce.ibmcloud.com/vulnerabilities/6985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912http://online.securityfocus.com/archive/1/205069http://www.ciac.org/ciac/bulletins/l-132.shtmlhttp://www.osvdb.org/5607https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044https://exchange.xforce.ibmcloud.com/vulnerabilities/6985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912
2001-09-20
Published
Exploited in the wild