RULE(RULE ID:305228)

Rule General Information
Release Date: 2015-01-06
Rule Name: Microsoft Webdav XML Message Handler Denial of Service Vulnerability -2 (CVE-2003-0718)
Severity:
CVE ID:
Rule Protection Details
Description: The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:ms04-030
Solutions
Microsoft has released a patch MS04-030 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms04-030.asp