CVE-2008-1446
published 2008-10-15CVE-2008-1446: Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4…
PriorityP276critical9CVSS 2.0
AVNACLAuSCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
46.27%
98.7th percentile
Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_information_services | 5.0 – 7.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2008-1446 is exploited via an HTTP POST request to the IPP ISAPI extension on Microsoft IIS 5.0–7.0, triggering an outbound IPP connection to an attacker-controlled machine; monitor for anomalous outbound IPP traffic originating from IIS web server processes. ↗
- ·Exploitation requires remote authenticated access; unauthenticated attackers cannot directly trigger the integer overflow in the IPP ISAPI extension. ↗
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w9v9-w8qx-wg82: Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5
ghsa_unreviewed·2022-05-01
CVE-2008-1446 [HIGH] CWE-190 GHSA-w9v9-w8qx-wg82: Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5
Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
VulnCheck
Microsoft Internet Information Services (IIS) Integer Overflow or Wraparound
vulncheck·2008·CVSS 9.0
CVE-2008-1446 [CRITICAL] Microsoft Internet Information Services (IIS) Integer Overflow or Wraparound
Microsoft Internet Information Services (IIS) Integer Overflow or Wraparound
Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
Affected: Microsoft Internet Information Services (IIS)
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en
No detection rules found.
No public exploits indexed.
Recorded Future
Underlying Dimensions of Yemen’s Civil War: Control of the Internet
blogs_recorded_future
Underlying Dimensions of Yemen’s Civil War: Control of the Internet
# Underlying Dimensions of Yemen’s Civil War: Control of the Internet
Scope Note: Sources of this research include the Recorded Future platform, Recorded Future malware detonation, the findings and methods from the Citizen Lab, Shodan, VirusTotal, Censys, ReversingLabs, and third-party metadata. Recorded Future would like to thank Rapid7 and their National Exposure Index in helping quantify the current IP landscape in Yemen. Recorded Future would also like to thank Joe Security for the use of their product to analyze Android device malware samples.
### Executive Summary
In the midst of the ongoing Yemeni civil war, local and international players are waging a secondary war through internet control and other cyber means. Recorded Future’s Insikt Group assesses that dynamics of the Yemeni
Recorded Future
Underlying Dimensions of Yemen’s Civil War: Control of the Internet
blogs_recorded_future
Underlying Dimensions of Yemen’s Civil War: Control of the Internet
## Underlying Dimensions of Yemen’s Civil War: Control of the Internet
Scope Note : Sources of this research include the Recorded Future platform, Recorded Future malware detonation, the findings and methods from the Citizen Lab, Shodan, VirusTotal, Censys, ReversingLabs, and third-party metadata. Recorded Future would like to thank Rapid7 and their National Exposure Index in helping quantify the current IP landscape in Yemen. Recorded Future would also like to thank Joe Security for the use of their product to analyze Android device malware samples.
## Executive Summary
In the midst of the ongoing Yemeni civil war, local and international players are waging a secondary war through internet control and other cyber means. Recorded Future’s Insikt Group assesses that dynamics of the Yemen
http://marc.info/?l=bugtraq&m=122479227205998&w=2http://secunia.com/advisories/32248http://www.kb.cert.org/vuls/id/793233http://www.securityfocus.com/bid/31682http://www.securitytracker.com/id?1021048http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlhttp://www.vupen.com/english/advisories/2008/2813https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-062https://exchange.xforce.ibmcloud.com/vulnerabilities/45545https://exchange.xforce.ibmcloud.com/vulnerabilities/45548https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5764http://marc.info/?l=bugtraq&m=122479227205998&w=2http://secunia.com/advisories/32248http://www.kb.cert.org/vuls/id/793233http://www.securityfocus.com/bid/31682http://www.securitytracker.com/id?1021048http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlhttp://www.vupen.com/english/advisories/2008/2813https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-062https://exchange.xforce.ibmcloud.com/vulnerabilities/45545https://exchange.xforce.ibmcloud.com/vulnerabilities/45548https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5764
2008-10-15
Published
Exploited in the wild