CVE-2010-1899 is a stack consumption vulnerability in the ASP implementation of Microsoft Internet Information Services (IIS) versions 5.1, 6.0, 7.0, and 7.5. A remote attacker can exploit this flaw by sending a specially crafted request, leading to a denial of service (daemon outage) due to stack exhaustion. The vulnerability has a CVSS score of 4.3 (medium severity) with a low attack complexity, requiring no authentication, and impacting availability. While not on the CISA KEV list, exploit modules exist in Metasploit and ExploitDB, indicating public exploit code availability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_server:6.0:*:*:*:*:*:*:* | ||
7.5CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_services:7.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.