CVE-2005-4360 describes a critical vulnerability in the URL parser of Microsoft IIS 5.1 on Windows XP Professional SP2, allowing remote attackers to execute arbitrary code. This is achieved by sending specific requests to ".dll" followed by arguments like "~0" through "~9", which leads to incorrect handling of ntdll.dll return values by IIS. The vulnerability has a high CVSS score of 7.8 (AV:N/AC:L/Au:N/C:N/I:C/A:N), indicating it can be exploited remotely with low complexity to achieve complete integrity impact, though it was initially believed to only cause a denial of service. While not listed in CISA's KEV catalog, exploit code for denial of service is available on ExploitDB, and the vulnerability has a high EPSS score, suggesting a significant probability of exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_services:5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:C/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.