← Vulnerability feed

Vulnerability record · CVE-2008-1446 · published 15 October 2008

CVE-2008-1446: Microsoft IIS IPP ISAPI integer overflow enables remote code execution

Microsoft · Internet Information Services

The Internet Printing Protocol (IPP) ISAPI extension in Microsoft IIS 5.0 through 7.0 contains an integer overflow that can be triggered by a crafted HTTP POST request. A remote authenticated user can cause the web server to make an outbound IPP connection to an attacker-controlled machine, corrupting memory and potentially executing arbitrary code in the IIS process context.

9.0 CVSS 2.0 High EPSS 46% · top 1.2% CWE-190 · Integer overflow
9.0CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution with complete confidentiality, integrity and availability impact, and although it requires authentication, the high EPSS score signals elevated exploitation likelihood.

What it is

The Internet Printing Protocol (IPP) ISAPI extension in Microsoft IIS 5.0 through 7.0 contains an integer overflow that can be triggered by a crafted HTTP POST request. A remote authenticated user can cause the web server to make an outbound IPP connection to an attacker-controlled machine, corrupting memory and potentially executing arbitrary code in the IIS process context.

Impact

An attacker who can authenticate to the web server gains the ability to run arbitrary code with the privileges of the IIS worker process, which typically means full control of the affected server.

Attack surface

Reached over the network via an HTTP POST to the IPP ISAPI extension; the vector requires authentication (Au:S) but no user interaction. The server must have the IPP service/ISAPI extension enabled and be able to initiate an outbound IPP connection to the attacker's host.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.46272, ~98.8th percentile), indicating meaningful predicted exploitation activity. All references are advisories, VDB entries or the vendor patch bulletin; none are tagged as exploit code.

What to do

  • Apply Microsoft security bulletin MS08-062 (the vendor patch) to all affected IIS versions.
  • Disable or remove the IPP ISAPI extension and the Internet Printing service on servers that do not require them.
  • Restrict outbound network connections from web servers so they cannot reach arbitrary attacker-controlled hosts.
  • Limit and audit accounts permitted to authenticate to IIS, since exploitation requires valid credentials.
  • Retire or isolate Windows 2000, XP, Server 2003 and Server 2008 systems running IIS 5.0-7.0 that cannot be patched.

Detection

  • Monitor IIS logs for POST requests to IPP-related ISAPI paths, especially from authenticated accounts.
  • Alert on unexpected outbound IPP traffic (TCP 631) originating from web servers.
  • Watch for IIS worker process crashes or abnormal memory behavior consistent with integer overflow exploitation.
  • Correlate authenticated web requests with subsequent outbound connections to unfamiliar external hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=122479227205998&w=2 Issue TrackingThird Party Advisory
http://secunia.com/advisories/32248 Third Party Advisory
http://www.kb.cert.org/vuls/id/793233 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/31682 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021048 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-288A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/2813 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-062 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45545 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45548 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5764 Third Party Advisory
http://marc.info/?l=bugtraq&m=122479227205998&w=2 Issue TrackingThird Party Advisory
http://secunia.com/advisories/32248 Third Party Advisory
http://www.kb.cert.org/vuls/id/793233 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/31682 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021048 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-288A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/2813 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-062 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45545 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45548 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5764 Third Party Advisory

Track CVE-2008-1446 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7269IIS 6.0 WebDAV ScStoragePathFromUrl buffer overflow enables remote code executionA buffer overflow in the ScStoragePathFromUrl function of the WebDAV service in IIS 6.0 on Windows Server 2003 R2 allows remote code execution via a …KEVEPSS 100%analysed10.0CVE-2010-3972Microsoft IIS FTP Service heap buffer overflow via crafted FTP commandA heap-based buffer overflow exists in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 as shipped w…EPSS 95%analysed10.0CVE-2008-4301Microsoft internet information services vulnerabilityA certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argum…EPSS 17%10.0CVE-2007-2815IIS 5.0 webhits.dll hit-highlighting authentication bypassThe hit-highlighting feature in webhits.dll on Microsoft IIS 5.0 relies only on Windows NT ACLs, so it fails to enforce NTLM or basic authentication.…EPSS 73%analysed10.0CVE-2003-0224Microsoft internet information services vulnerabilityBuffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a…EPSS 18%10.0CVE-1999-0233Microsoft internet information services vulnerabilityIIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.EPSS 16%9.3CVE-2010-2730Microsoft internet information services memory buffer overflow vulnerabilityBuffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via …EPSS 33%7.8CVE-2005-4360Microsoft IIS URL parser unchecked return value enables remote code executionThe URL parser in Microsoft IIS 5.1 on Windows XP Professional SP2 mishandles a return value from ntdll.dll when a request targets a ".dll" path foll…EPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1446), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.