← Vulnerability feed

Vulnerability record · CVE-2006-1364 · published 23 March 2006

CVE-2006-1364: Microsoft ASP.NET w3wp COM component handling denial of service

Microsoft · Asp.Net

Microsoft w3wp.exe mishandles requests for ASP.NET documents that reference COM components without the AspCompat directive, leading to uncontrolled resource consumption or a crash. Repeatedly requesting such documents, or restricted documents under the ASP.NET application path, can exhaust resources and take the worker process down. The flaw matters because it is remotely reachable without authentication and affects the web server process itself.

7.5 CVSS 3.0 High EPSS 59% · top 0.9% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.0 base score, v2 7.8
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated denial of service with public exploit references and very high EPSS, though no KEV listing and impact limited to availability.

What it is

Microsoft w3wp.exe mishandles requests for ASP.NET documents that reference COM components without the AspCompat directive, leading to uncontrolled resource consumption or a crash. Repeatedly requesting such documents, or restricted documents under the ASP.NET application path, can exhaust resources and take the worker process down. The flaw matters because it is remotely reachable without authentication and affects the web server process itself.

Impact

An attacker can cause denial of service through resource consumption or a crash of the w3wp worker process, disrupting hosted ASP.NET applications. No confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable over the network via HTTP requests to ASP.NET documents that reference COM components or restricted documents under the application path. The CVSS vector shows no privileges and no user interaction required.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.587, 99th percentile) and multiple references are tagged Exploit, including Exploit-DB 1601 and SecurityFocus BID 17188, indicating public exploit material exists.

What to do

  • Apply the vendor fix for the affected ASP.NET/w3wp component; this is a 2006 issue, so confirm current patch level or supported platform status first.
  • Where COM interop is used, ensure the AspCompat directive is applied to the relevant ASP.NET pages.
  • Restrict or remove public access to restricted documents located under the ASP.NET application path.
  • Rate-limit and monitor repeated requests to COM-referencing pages at the reverse proxy or WAF.
  • Isolate or recycle the application pool to limit blast radius of worker process crashes.

Detection

  • Monitor w3wp.exe for abnormal memory growth, CPU spikes or unexpected process restarts.
  • Alert on repeated HTTP requests to the same ASP.NET documents that reference COM components from a single source.
  • Review IIS and Windows application logs for worker process crash or recycle events correlated with request bursts.
  • Baseline normal request rates to COM-interop pages and flag deviations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-1364 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2004-0847ASP.NET forms authentication bypass via backslash path traversalASP.NET forms authentication can be bypassed for .aspx files in restricted directories by sending a request containing a backslash or its encoded for…EPSS 76%analysed6.8CVE-2003-0768Microsoft asp.net vulnerabilityMicrosoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character i…EPSS 13%6.4CVE-2005-1664Microsoft asp.net vulnerabilityThe __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one …EPSS 19%5.0CVE-2005-2224Microsoft asp.net vulnerabilityaspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a craft…EPSS 18%5.0CVE-2005-1665Microsoft asp.net vulnerabilityThe __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU …EPSS 40%4.3CVE-2010-2084Microsoft asp.net cross-site scripting vulnerabilityMicrosoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attac…EPSS 13%4.3CVE-2010-2088Microsoft asp.net cross-site scripting vulnerabilityASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS)…EPSS 9.0%4.3CVE-2005-0452Microsoft asp.net vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or…EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2006-1364), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.