microsoft internet-information-services CVE-2010-3972 is a vulnerability in Microsoft Internet Information Services
Published on December 23, 2010

Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka "IIS FTP Service Heap Buffer Overrun Vulnerability." NOTE: some of these details are obtained from third party information.

Vendor Advisory NVD


Products Associated with CVE-2010-3972

Want to know whenever a new CVE is published for Microsoft Internet Information Services? stack.watch will email you.

 

Exploit Probability

EPSS
91.69%
Percentile
99.67%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.