Security Best Practice: Protect Yourself from Invalid IIS ASP.Net URI Character Requests
| Check Point Reference: | SBP-2009-15 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS09-036 | |
| Industry Reference(s): | CVE-2009-1536 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Microsoft .NET Framework 2.0 on: Windows Vista Windows Vista x64 Edition Windows Server 2008 Microsoft .NET Framework 2.0 SP1 on: Microsoft .NET Framework 2.0 SP2 on: | ||
| Vulnerability Description A denial of service vulnerability has been reported in ASP.NET. ASP.NET is a collection of technologies within the.NET Framework that enable developers to build Web applications and XML Web Services. A remote attacker may exploit this issue to cause a vulnerable server to become non-responsive. |
||
|
Vulnerability Details This vulnerability is due to an error in ASP.NET that fails to correctly manage request scheduling. An attacker could exploit this vulnerability by creating a specially crafted series of anonymous HTTP requests to an affected system. Successful exploitation of this vulnerability could cause the application pool on the affected Web server to become non-responsive. As a result, Web pages that use ASP.NET in the same application pool would no longer be reachable and would return an HTTP error. |
Protection Overview
This protection will detect and block IIS ASP.Net requests with invalid characters in the URI.
In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.