Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-3023

88
FAUCET Score

CVE-2009-3023 describes a critical buffer overflow vulnerability in the FTP Service of Microsoft IIS versions 5.0 through 6.0, impacting Windows 2000, XP, Server 2003, and Server 2008. This flaw allows remote authenticated users to execute arbitrary code or cause a denial of service by sending a specially crafted NLST command with wildcards, leading to memory corruption. With a CVSS score of 9.0, it is a high-severity vulnerability, easily exploitable over the network with low attack complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, exploit intelligence indicates the existence of multiple public exploit modules, including a Metasploit module and several ExploitDB entries, though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0, <= 6.0CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_information_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.0HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
90.91%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Metasploit: MS09-053 Microsoft IIS FTP Server NLST Response Overflow · Aug 31, 2009
ExploitDB: EDB-16740 · Nov 12, 2010
This CVE's current EPSS score of 0.9091 is in the 100th percentile among its peer group of 17,822 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.microsoft.com / en-us/security-updates/securitybulletins/2009/ms09-053
PatchVendor Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6080
Third Party Advisory
support.microsoft.com / default.aspx
exploit-db.com / exploits/9541
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/9559
ExploitThird Party AdvisoryVDB Entry
kb.cert.org / vuls/id/276653
Third Party AdvisoryUS Government Resource
securityfocus.com / bid/36189
ExploitThird Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA09-286A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2009/2481
Third Party Advisory