IIS 4.0 Denial of Service Vulnerability

HIGH (10.0) No Patch (9681 days)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 83.54% chance of exploitation (percentile: 99%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: Exploit-DB

How we test →

What is it?

The IIS 4.0 web server is a widely used software for hosting websites and web applications. This vulnerability allows remote attackers to cause a denial of service by sending a malformed request for files with specific extensions, such as .HTR, .IDC, or .STM.

Am I affected?

You're affected if you use Microsoft Internet Information Services (IIS) version 4.0. Check with: dir /b /s %windir%\system32\inetsrv\httpd.dll to verify the presence of the httpd.dll file.

Note: This vulnerability is specific to IIS 4.0 and not related to other Microsoft products or services.

Affected Products

Microsoft / IIS 4.0

How to fix

To fix this vulnerability, you can upgrade to a newer version of IIS that includes a patch for this issue. You can download the update from the Microsoft Support website:

Immediate mitigations:

  • Restrict network access to your IIS 4.0 server (firewall it from the public internet)
  • Monitor for unusual system activity and potential denial of service attacks