Vulnerability record · CVE-2006-1364 · published 23 March 2006
CVE-2006-1364: Microsoft ASP.NET w3wp COM component handling denial of service
Microsoft · Asp.Net
Microsoft w3wp.exe mishandles requests for ASP.NET documents that reference COM components without the AspCompat directive, leading to uncontrolled resource consumption or a crash. Repeatedly requesting such documents, or restricted documents under the ASP.NET application path, can exhaust resources and take the worker process down. The flaw matters because it is remotely reachable without authentication and affects the web server process itself.
Description
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated denial of service with public exploit references and very high EPSS, though no KEV listing and impact limited to availability.
What it is
Microsoft w3wp.exe mishandles requests for ASP.NET documents that reference COM components without the AspCompat directive, leading to uncontrolled resource consumption or a crash. Repeatedly requesting such documents, or restricted documents under the ASP.NET application path, can exhaust resources and take the worker process down. The flaw matters because it is remotely reachable without authentication and affects the web server process itself.
Impact
An attacker can cause denial of service through resource consumption or a crash of the w3wp worker process, disrupting hosted ASP.NET applications. No confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via HTTP requests to ASP.NET documents that reference COM components or restricted documents under the application path. The CVSS vector shows no privileges and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.587, 99th percentile) and multiple references are tagged Exploit, including Exploit-DB 1601 and SecurityFocus BID 17188, indicating public exploit material exists.
What to do
- Apply the vendor fix for the affected ASP.NET/w3wp component; this is a 2006 issue, so confirm current patch level or supported platform status first.
- Where COM interop is used, ensure the AspCompat directive is applied to the relevant ASP.NET pages.
- Restrict or remove public access to restricted documents located under the ASP.NET application path.
- Rate-limit and monitor repeated requests to COM-referencing pages at the reverse proxy or WAF.
- Isolate or recycle the application pool to limit blast radius of worker process crashes.
Detection
- Monitor w3wp.exe for abnormal memory growth, CPU spikes or unexpected process restarts.
- Alert on repeated HTTP requests to the same ASP.NET documents that reference COM components from a single source.
- Review IIS and Windows application logs for worker process crash or recycle events correlated with request bursts.
- Baseline normal request rates to COM-interop pages and flag deviations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-1364 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-1364), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.