RULE(RULE ID:205495)

Rule General Information
Release Date: 2019-07-06
Rule Name: Microsoft IIS FTP Server NLST Long Directory Name Buffer Overflow Vulnerability (CVE-2009-3023)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://support.microsoft.com/default.aspx?scid=kb
ExploitDB:9541
SecurityFocusBID:36189
MicrosoftSecurityBulletin:ms09-053
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.microsoft.com/en-us/default.aspx