AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2521

MEDIUM · CVSS 5 EPSS 82.27%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-09-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-2521
Severity
MEDIUM
CVSS
5
EPSS
82.27%
Microsoft

Original NVD Description

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."