4.3
CVSSv2

CVE-2017-0055

Published: 17/03/2017 Updated: 12/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote malicious users to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2012 -

microsoft windows server 2012 r2

microsoft windows 10 1607

microsoft windows rt 8.1

microsoft windows vista

microsoft windows server 2016

microsoft windows 8.1

microsoft windows 7

microsoft windows 10 -

microsoft windows 10 1511

microsoft windows server 2008

microsoft windows server 2008 r2

Exploits

Microsoft Internet Information Services web server suffers from a cross site scripting vulnerability ...

Github Repositories

Proof of Concept Sometime sound looks like "Poop of Concept" πŸ’© Index Generated with laziness β”œβ”€β”€ Pwned β”‚   └── CVE-2017-0055\ MS\ IIS\ 70-10\ XSSmd └── READMEmd 1 directory, 2 files

This it's a PoC of Departament of justice VDP. By rootkit

CVE-2017-0055 PoC MICROSOFT IIS 70/75/80/85/10 /UNCPATH/ CROSS SITE SCRIPTING Reference: nvdnistgov/vuln/detail/CVE-2017-0055 Base Score: 61 Severity: Medium Exploit: vulniis/uncpath/%3Cimg%20onerror=alert('xss')%20src=/%3E:/