AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2011-5279

MEDIUM · CVSS 5 EPSS 18.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-04-23 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2011-5279
Severity
MEDIUM
CVSS
5
EPSS
18.97%
Microsoft Windows

Original Filing — NVD Description

CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.