CVE-2017-7269General(microsoft / internet_information_services)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft internet_information_services systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_information_services
  • windows_server_2003

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-01); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
internet_information_serviceswindows_server_2003

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-01: 1Mentions · 2026-06-13: 1Mentions · 2026-08-03: 1Mentions · 2026-08-22: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-22: 1Exploit Tool / Code · 2026-08-03: 1Patch / Workaround · 2026-06-13: 1Technical Details · 2026-03-01: 1Technical Details · 2026-06-13: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-22: 103-0106-1308-0308-22
Signal classification2 categories
General
250.0%
PoC
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-011
General1
2026-06-131
General1
2026-08-031
PoC1
2026-08-221
PoC1
Full discourse4 posts
  • Ch4rl3s K00m3@CharlesKoome6
    PoC

    New writeup: Grandpa @hackthebox_eu easy Windows box running IIS 6.0 on Server 2003. WebDAV RCE (CVE-2017-7269) → SYSTEM. Full chain 👇 https://blog.charleskoome.com/posts/grandpa-hackthebox-writeup/ #HackTheBox #PenetrationTesting #CyberSecurity

    Post summary

    The post presents a proof‑of‑concept writeup for CVE-2017-7269, showcasing a WebDAV RCE to SYSTEM on IIS 6.0, but does not provide exploit code, claim ongoing attacks, or mention patches.

    00031128
    1.2K followersView on X
  • Master Goblin@Alex_Kuein
    General

    Shodan shows 50k+ servers that still use IIS 6.0 If you see IIS/6.0 in a server header on a public-facing IP, treat it as compromised until proven otherwise. There is no official Microsoft patch for CVE-2017-7269, which affects IIS 6.0 specifically. #cybersecurity

    Post summary

    The post highlights that 50k+ IIS 6.0 servers are exposed to CVE‑2017‑7269, notes the absence of an official Microsoft patch, and advises treating any server reporting IIS/6.0 as compromised until verified otherwise.

    1001058
    118 followersView on X
  • Abdullah (IPinfo DevRel)@reincdr
    General

    WebDAV probe checking for IIS 6.0 buffer overflow (CVE-2017-7269) or misconfigured file upload access. Many threat intel services do not recognize these IPs as malicious, but you can identify them as hosting type IPs and block them. https://t.co/GvNtp494We

    Post summary

    The message outlines using a WebDAV probe to detect the IIS 6.0 buffer overflow vulnerability CVE‑2017‑7269 and suggests identifying and blocking suspicious IPs, without providing PoC, exploit tools, or patch details.

    0001094
    232 followersView on X
  • Ch4rl3s K00m3@CharlesKoome6
    PoC

    New writeup: Granny (Easy Windows — HackTheBox) Vintage IIS 6.0 + WebDAV → CVE-2017-7269 buffer overflow → NETWORK SERVICE → Metasploit local exploit suggester → kernel privesc → SYSTEM. Old tech, clean chain. Full walkthrough https://blog.charleskoome.com/posts/granny-writeup/ #HTB #CTF #Windows

    Post summary

    The post announces a walkthrough for the CVE‑2017‑7269 IIS buffer overflow, detailing the exploitation chain and linking to a full guide that includes a Metasploit module.

    0000075
    1.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftinternet_information_services6.0--
OSmicrosoftwindows_server_2003r2--

Explore more