cbcvebase.
CVE-2009-1122
published 2009-06-10

CVE-2009-1122: The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to…

PriorityP273high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
98.45%
99.9th percentile
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftinternet_information_services
microsoftinternet_information_services
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

url%c0%af
  • Detect HTTP requests to IIS WebDAV endpoints containing the overlong UTF-8 sequence %c0%af (Unicode slash) anywhere in the URI path, which is used to bypass authentication on protected folders.
  • The vulnerability is exploitable where WebDAV is enabled on IIS 6.0 and protected folders require Basic, Digest, or NTLM authentication — scope detection to IIS 6.0 servers with WebDAV active.
  • ·This CVE (CVE-2009-1122) is noted as a distinct but related vulnerability to CVE-2009-1535; both involve %c0%af Unicode bypass on IIS WebDAV but are separate issues — ensure detection rules target both CVEs independently.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.