CVE-2007-0087
Last modified
CVE-2007-0087 is a vulnerability of currently unknown severity. Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal. EPSS estimates a 23.16% chance of exploitation in the next 30 days.
Description
Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Information Server | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0087?
How severe is CVE-2007-0087?
How do I fix CVE-2007-0087?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0081Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, …
- CVE-2007-0082users_adm/start1.php in IMGallery 2.5 and earlier does not p…
- CVE-2007-0083Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 a…
- CVE-2007-0084Buffer overflow in the Windows NT Message Compiler (MC) 1.00…
- CVE-2007-0085Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VG…
- CVE-2007-0086The Apache HTTP Server, when accessed through a TCP connecti…
- CVE-2007-0088Multiple directory traversal vulnerabilities in openmedia al…
- CVE-2007-0089jgbbs stores sensitive information under the web root with i…
- CVE-2007-0090WineGlass stores sensitive information under the web root wi…
- CVE-2007-0091newsCMSlite stores sensitive information under the web root …
- CVE-2007-0092SQL injection vulnerability in productdetail.asp in E-SMARTC…
- CVE-2007-0093SQL injection vulnerability in page.php in Simple Web Conten…
Are you affected by CVE-2007-0087?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
