Knowledge

4/3/2017

Hard Reminder to Upgrade Windows 2003 Servers: Microsoft Will Not Fix New Vulnerability

New remote execution vulnerability (CVE-2017-7269) was recorded in the National Vulnerability Database for Windows 2003 R2 IIS6 last week. Exploitation of this vulnerability allows a remote attacker to execute code on the vulnerable web server. 

Thus, potentially allowing hackers to take over the whole system, install remote control systems and propagate within local network conducting local attacks. Results of the exploitation might be catastrophic for organizations. Microsoft will not provide a patch for this vulnerability, as OS is not officially supported. 

The Digital Edge Security Team has analyzed exploitation possibilities. Even if there is a serious possibility to exploit such vulnerabilities, we discovered the following:

  1. We could not exploit the vulnerability over SSL. In this case, server was terminating connection. 
  2. We could not exploit the vulnerability if .NET application is enable on the web site. The server was logging security error: “path 'PROPFIND' is forbidden”. So .NET script map does not allow “PROPFIND” verb. 

When you really should worry:

  1. If you use WebDAW protocol. 
  2. If you don’t know if you are using or not using WebDAW protocol. 

What you can do to mitigate:

  1. Update to newer version of Windows. 
  2. Disable WebDAV protocol. 

Further, Digital Edge LogIT Services were updated to include PROPFIND error message in the security triggers for the customers who use our service. 

Digital Edge LogIT Service gives clients an ability to collect system logs and create security alerts based on Digital Edge’s experience working in the IT Security Area. 

Read more about LogIT here

Michael Petrov
Founder, Chief Executive Officer

Michael brings 30 years of experience as an information architect, optimization specialist and operations’ advisor. His experience includes extensive high-profile project expertise, such as mainframe and client server integration for Mellon Bank, extranet systems for Sumitomo Bank, architecture and processing workflow for alternative investment division of US Bank. Michael possesses advanced knowledge of security standards such as ISO 27001, NIST, SOC and PCI that brings into any solutions delivered by Digital Edge. Security solutions and standards are expended into public cloud such as AWS and Azure.