AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-6578

HIGH · CVSS 7.5 EPSS 6.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-12-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-6578
Severity
HIGH
CVSS
7.5
EPSS
6.97%
Microsoft

Original NVD Description

Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.