Vulnerability record · CVE-2003-0718 · published 3 November 2004
CVE-2003-0718: IIS WebDAV PROPFIND XML attribute flood denial of service
Microsoft · Internet Information Server
The WebDAV Message Handler in IIS 5.0, 5.1 and 6.0 fails to handle PROPFIND requests containing XML elements with an excessive number of attributes, causing memory and CPU exhaustion and application crash. The flaw is remotely reachable and unauthenticated, so any host exposing WebDAV can be knocked over with a crafted request.
Description
The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote denial of service with very high EPSS despite no KEV listing, though the affected IIS versions are long obsolete.
What it is
The WebDAV Message Handler in IIS 5.0, 5.1 and 6.0 fails to handle PROPFIND requests containing XML elements with an excessive number of attributes, causing memory and CPU exhaustion and application crash. The flaw is remotely reachable and unauthenticated, so any host exposing WebDAV can be knocked over with a crafted request.
Impact
An attacker can exhaust server memory and CPU and crash the IIS WebDAV handler, denying service to legitimate users. No data confidentiality or integrity loss is described; the effect is availability only.
Attack surface
Reached over the network via an HTTP PROPFIND request to the WebDAV handler, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is very high (0.879, 99.8th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply Microsoft security bulletin MS04-030, which addresses this WebDAV flaw, or upgrade off the affected IIS 5.0/5.1/6.0 builds.
- If WebDAV is not required, disable it on IIS to remove the attack surface entirely.
- Restrict network access to WebDAV endpoints with firewall or reverse-proxy rules, allowing only trusted clients.
- Enable request filtering and request-size limits so oversized PROPFIND bodies are rejected before reaching the handler.
Detection
- Alert on PROPFIND requests with unusually large bodies or XML elements carrying an abnormal number of attributes.
- Monitor IIS worker process (w3wp.exe) memory and CPU spikes correlated with WebDAV request bursts.
- Log and baseline PROPFIND source IPs; flag single sources generating high volumes of PROPFIND traffic.
- Watch for IIS application crash or worker process recycle events following WebDAV activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0718 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0718), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.