Vulnerability record · CVE-2008-1446 · published 15 October 2008
CVE-2008-1446: Microsoft IIS IPP ISAPI integer overflow enables remote code execution
Microsoft · Internet Information Services
The Internet Printing Protocol (IPP) ISAPI extension in Microsoft IIS 5.0 through 7.0 contains an integer overflow that can be triggered by a crafted HTTP POST request. A remote authenticated user can cause the web server to make an outbound IPP connection to an attacker-controlled machine, corrupting memory and potentially executing arbitrary code in the IIS process context.
Description
Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with complete confidentiality, integrity and availability impact, and although it requires authentication, the high EPSS score signals elevated exploitation likelihood.
What it is
The Internet Printing Protocol (IPP) ISAPI extension in Microsoft IIS 5.0 through 7.0 contains an integer overflow that can be triggered by a crafted HTTP POST request. A remote authenticated user can cause the web server to make an outbound IPP connection to an attacker-controlled machine, corrupting memory and potentially executing arbitrary code in the IIS process context.
Impact
An attacker who can authenticate to the web server gains the ability to run arbitrary code with the privileges of the IIS worker process, which typically means full control of the affected server.
Attack surface
Reached over the network via an HTTP POST to the IPP ISAPI extension; the vector requires authentication (Au:S) but no user interaction. The server must have the IPP service/ISAPI extension enabled and be able to initiate an outbound IPP connection to the attacker's host.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.46272, ~98.8th percentile), indicating meaningful predicted exploitation activity. All references are advisories, VDB entries or the vendor patch bulletin; none are tagged as exploit code.
What to do
- Apply Microsoft security bulletin MS08-062 (the vendor patch) to all affected IIS versions.
- Disable or remove the IPP ISAPI extension and the Internet Printing service on servers that do not require them.
- Restrict outbound network connections from web servers so they cannot reach arbitrary attacker-controlled hosts.
- Limit and audit accounts permitted to authenticate to IIS, since exploitation requires valid credentials.
- Retire or isolate Windows 2000, XP, Server 2003 and Server 2008 systems running IIS 5.0-7.0 that cannot be patched.
Detection
- Monitor IIS logs for POST requests to IPP-related ISAPI paths, especially from authenticated accounts.
- Alert on unexpected outbound IPP traffic (TCP 631) originating from web servers.
- Watch for IIS worker process crashes or abnormal memory behavior consistent with integer overflow exploitation.
- Correlate authenticated web requests with subsequent outbound connections to unfamiliar external hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1446 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1446), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.