What happened
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
Affected versions
Internet Information Services (IIS): See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 41992Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)Metasploit2017-05-11VerifiedExploit-DB 41738Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer OverflowZhiniang Peng & Chen Wu2017-03-27VerifiedSploitusCVE-2017-7269 affects the tools repository, which lacks a README file.KitPloit2026-08-25T13:52:51Candidatekitploit.comCVE-2017-7269 affects the tools repository, which lacks a README file.ko2026-08-25T13:52:51CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.