cbcvebase.
CVE-2001-0507
published 2001-09-20

CVE-2001-0507: IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System…

PriorityP270high7.2CVSS 2.0
AVLACLAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
4.45%
90.3th percentile
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

filenameIISCrack.dll
filenamehttpodbc.dll
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/21072.zip
  • Monitor for creation or modification of httpodbc.dll in IIS 5.0 directories, which may indicate DLL side-loading abuse via CVE-2001-0507.
  • Detect presence of IISCrack.dll on disk, particularly in IIS-related paths, as it is used by FIN13 for DLL side-loading privilege escalation.
  • Alert on any local user with write permissions to IIS 5.0 in-process directories executing code at SYSTEM privilege level, consistent with the vulnerability's exploitation path.
  • ·CVE-2001-0507 only affects IIS 5.0 and relies on relative path resolution for in-process system files; exploitation requires a local user with write permissions to the relevant directory.

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.