CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It affects Microsoft. Its EPSS score suggests a 63.2% probability of exploitation in the next 30 days. It may be remotely exploitable. It may lead to a denial-of-service condition.
CVE
CVE-2001-1243
Severity
MEDIUM
CVSS
5
EPSS
63.19%
Microsoft
Original NVD Description
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.