Skip to main content

CVE detail

CVE-2017-7269

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

CVSS 9.8 · CriticalBuzz score 64.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 64.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
22 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
22 source links · newest first
  • ed inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit ( CVE-2021-4034 ), the sudo heap overflow ( CVE-2021-3156 ), and the long-standing IIS WebDAV vulnerability ( CVE-2017-7269 ). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems en

    newssecurityaffairs.comJul 24, 2026, 12:10 PM
  • While cryptomining services such as Coinhive have closed down, cryptominers are still the most prevalent malware aimed at organizations globally, according to the Check Point Global Threat Index for March 2019. As announced last month, both Coinhive and Authedmine stopped their mining services on March 8th. For the first time since December 2017, Coinhive dropped from the Index’s top position but, despite having only operated for eight days in March, it was still the 6th … More →

    newswww.helpnetsecurity.comApr 10, 2019, 5:15 AM
  • Coinhive has once again led Check Point’s Global Threat Index for the 15th consecutive month, despite the announcement that its services have been shut down from March 8th 2019. GandCrab ransomware Researchers have also discovered several widespread campaigns distributing the GandCrab ransomware that have targeted Japan, Germany, Canada and Australia. These nations are just part of the targeted countries. These operations have emerged over the last two months, and Check Point’s researchers noticed a new … More →

    newswww.helpnetsecurity.comMar 12, 2019, 6:15 AM
  • 2018 saw the convergence of three separate threat trends — two that have evolved over the last few years, and one that came to the fore during 2018. These are the merging of IoT botnets, destructive malware and cryptojacking.

    newswww.securityweek.comFeb 20, 2019, 2:31 PM
  • Check Point’s Global Threat Index for January 2019 reveals a new backdoor Trojan affecting Linux servers, which is distributing the XMRig crypto-miner. The new malware, dubbed SpeakUp, is capable of delivering any payload and executing it on compromised machines. The new Trojan currently evades all security vendors’ anti-virus software. It has been propagated through a series of exploitations based on commands it receives from its control center, including the 8th most popular exploited vulnerability, “Command … More →

    newswww.helpnetsecurity.comFeb 14, 2019, 6:15 AM
  • Check Point has published its latest Global Threat Index for December 2018. The index reveals that SmokeLoader, a second-stage downloader known to researchers since 2011, rose 11 places in December to enter the Index’s top 10 at ninth place. After a surge of activity in the Ukraine and Japan, its global impact grew by 20. SmokeLoader is mainly used to load other malware, such as Trickbot Banker, AZORult Infostealer and Panda Banker. Cryptomining malware continues … More →

    newswww.helpnetsecurity.comJan 15, 2019, 6:00 AM
  • November 2018: Most wanted malware exposedHelp Net Security

    Check Point has published its latest Global Threat Index for November 2018. The index reveals that the Emotet botnet has entered the Index’s top 10 ranking after researchers saw it spread through several campaigns, including a Thanksgiving-themed campaign. This involved sending malspam emails in the guise of Thanksgiving cards, containing email subjects such as happy “Thanksgiving day wishes”, “Thanksgiving wishes” and “the Thanksgiving day congratulation!” These emails contained malicious attachments, often with file names related … More →

    newswww.helpnetsecurity.comDec 12, 2018, 6:15 AM
  • The latest Check Point Global Threat Index reveals that while cryptomining malware continues to dominate the rankings, a remote access Trojan has reached the top ten’s list for the first time. During the month of October, Check Point researchers discovered a widespread malware campaign spreading a remote access trojan (dubbed “FlawedAmmy”) that allows attackers to take over victims’ computers and data. The campaign was the latest and most widespread delivering the ‘FlawedAmmyy’ RAT, following a … More →

    newswww.helpnetsecurity.comNov 14, 2018, 6:15 AM
  • Check Point has published its latest Global Threat Index for September 2018, revealing a near-400% increase in cryptomining malware attacks against Apple iPhones. These attacks are using the Coinhive mining malware, which continues to occupy the top position in the Index that it has held since December 2017. Coinhive now impacts 19% of organizations worldwide. Check Point’s researchers also observed a significant increase in Coinhive attacks against PCs and devices using the Safari browser, which … More →

    newswww.helpnetsecurity.comOct 16, 2018, 5:30 AM
  • Check Point revealed a significant increase in attacks using the Ramnit banking trojan. Ramnit has doubled its global impact over the past few months, driven by a large scale campaign that has been converting victim’s machines into malicious proxy servers. Ramnit “black” botnet geography During August 2018, Ramnit became the most prevalent banking Trojan in an upward trend in the use of banking Trojans that has more than doubled since June 2018. “This is the … More →

    newswww.helpnetsecurity.comSep 12, 2018, 5:45 AM
  • Supply Chain Attack Hits South Korean Firms Security researchers from Trend Micro have uncovered a supply chain attack, tracked as Operation Red Signature, against organizations in South Korea. The Operation Red Signature aimed at delivering a remote access Trojan (RAT) used by attackers to steal sensitive information from the victims. Threat actors compromised update server of a remote support […]

    newssecurityaffairs.comAug 23, 2018, 6:53 AM
  • Security researchers have uncovered a supply chain attack aimed at infecting organizations in South Korea with a remote access Trojan (RAT) to steal valuable information.

    newswww.securityweek.comAug 22, 2018, 2:37 PM
  • Check Point published its latest Global Threat Index for May 2018, revealing that the Coinhive cryptominer impacted 22% of organizations globally – up from 16% in April, an increase of nearly 50%. May 2018 marked the fifth consecutive month where cryptomining malware dominated Check Point’s Top Ten Most Wanted Malware Index. Coinhive retained the top spot as the most prevalent malware with Cryptoloot – another crypto-mining malware – ranked second with a global reach of … More →

    newswww.helpnetsecurity.comJun 8, 2018, 11:45 AM
  • Hundreds of servers have been infected with Monero mining malware after miscreants managed to exploit a vulnerability in Microsoft IIS 6.0, ESET warns.

    newswww.securityweek.comSep 29, 2017, 12:38 PM
  • Experts from security firm ESET discovered cyber criminals exploiting Microsoft Servers to mine Monero and already earned $63,000 in 3 Months. Mining cryptocurrencies is a profitable business, but it is also expensive because it needs significant investment in computing power. Crooks are using malicious code that steals computing resources of victims’ machine and the number of […]

    newssecurityaffairs.comSep 29, 2017, 9:21 AM
  • Third-party risk and understanding that risk continues to grow; but mitigation of the risk is, if anything, getting worse. This can be seen in two separate studies published this week by Ponemon and BitSight.

    newswww.securityweek.comSep 28, 2017, 12:28 PM
  • Siemens has informed customers that some of its molecular imaging products are exposed to remote attacks due to vulnerabilities affecting Windows and other third-party components.

    newswww.securityweek.comAug 4, 2017, 3:23 PM
  • While Microsoft releasing a patch for unsupported versions of Windows to fix vulnerabilities that could be exploited by the hacking tools dumped by the ShadowBrokers helps organizations hanging onto legacy systems, it also makes the case for keep these systems around even longer. Enterprises hanging on to old software years after it is no longer […]

    newswww.csoonline.comJun 15, 2017, 7:02 PM
  • Microsoft has released patches for Windows XP and other outdated versions of the operating system to fix several critical vulnerabilities that are at heightened risk of being exploited by state-sponsored actors and other threat groups.

    newswww.securityweek.comJun 14, 2017, 9:02 AM
  • Microsoft Internet Information Services (IIS) 6.0 sports a zero-day vulnerability (CVE-2017-7269) that was exploited in the wild last summer and is likely also being exploited by threat actors at this very moment. It is a buffer overflow flaw in a function in the WebDAV service in IIS 6.0 in Microsoft Windows Server 2003 R2, and can be triggered by attackers sending a overlong IF header in a PROPFIND request. Unfortunately, the flaw won’t be patched … More →

    newswww.helpnetsecurity.comMar 30, 2017, 2:15 PM
  • Millions of websites are affected by a buffer overflow zero-day vulnerability, tracked as CVE-2017-7269, that resides in the IIS 6.0. The II6 6.0 zero-day flaw was discovered by two researchers with the Information Security Lab & School of Computer Science & Engineering, South China University of Technology Guangzhou, China who published a PoC code exploit on GitHub. […]

    newssecurityaffairs.comMar 29, 2017, 6:11 PM
  • More than 8 million websites could be exposed to a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 that has been exploited in the wild since July 2016, researchers warn.

    newswww.securityweek.comMar 29, 2017, 4:52 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence