Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-2509 | First vendor Publication | 2009-12-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2509 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:6441 | |||
Oval ID: | oval:org.mitre.oval:def:6441 | ||
Title: | Remote Code Execution in ADFS Vulnerability | ||
Description: | Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-2509 | Version: | 5 |
Platform(s): | Microsoft Windows Server 2003 Microsoft Windows Server 2008 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2009-12-09 | Name : Microsoft Windows ADFS Remote Code Execution Vulnerability (971726) File : nvt/secpod_ms09-070.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
60836 | Microsoft Windows Active Directory Federation Services (ADFS) Request Header ... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2009-12-10 | IAVM : 2009-A-0125 - Multiple Vulnerabilities in Microsoft Active Directory Federation Services (A... Severity : Category II - VMSKEY : V0022100 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Active Directory Federation Services code execution attempt RuleID : 20675 - Revision : 5 - Type : SERVER-IIS |
2014-01-10 | ADFS custom header arbitrary code execution attempt RuleID : 16312 - Revision : 6 - Type : SERVER-IIS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-12-08 | Name : Arbitrary code can be executed on the remote host through Microsoft Active Di... File : smb_nt_ms09-070.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:48 |
|
2024-11-28 12:19:26 |
|
2021-05-04 12:09:50 |
|
2021-04-22 01:10:11 |
|
2020-05-23 00:24:03 |
|
2019-02-26 17:19:32 |
|
2018-10-13 00:22:50 |
|
2017-09-19 09:23:18 |
|
2016-08-31 12:01:50 |
|
2016-06-28 17:46:13 |
|
2016-04-26 18:58:51 |
|
2014-02-17 10:50:51 |
|
2014-01-19 21:26:02 |
|
2013-11-11 12:38:22 |
|
2013-05-10 23:54:12 |
|