Vulnerability of IIS 5.1: shell command execution

Synthesis of the vulnerability 

An attacker allowed to upload ASP files can run shell commands.
Vulnerable software: IIS.
Severity of this announce: 1/4.
Number of vulnerabilities in this bulletin: 2.
Creation date: 21/12/2006.
Références of this computer vulnerability: CVE-2006-6578, CVE-2006-6579, VIGILANCE-VUL-6421.

Description of the vulnerability 

IIS web server uses two users:
 - IUSR_computer: access to pages
 - IWAM_computer: start process

Since version 5.1, an ASP script cannot execute a shell as IUSR_computer. However, two vulnerabilities permit to bypass this restriction.

Script can use to start cmd.exe. [severity:1/4; CVE-2006-6578]

Script can create and read files in %WINDIR%\pchealth\ERRORREP\QHEADLES in order to obtain stdout data. [severity:1/4; CVE-2006-6579]
Our Vigil@nce team determined that the severity of this vulnerability alert is low.

Solutions for this threat 

