Vulnerability record · CVE-2009-1122 · published 10 June 2009
CVE-2009-1122: IIS 5.0 WebDAV URL decoding flaw allows authentication bypass
Microsoft · Internet Information Services
The WebDAV extension in Microsoft IIS 5.0 on Windows 2000 SP4 fails to properly decode URLs, letting a remote attacker bypass authentication with a crafted HTTP request. Because the flaw defeats the authentication check itself, it undermines the primary access control protecting WebDAV resources. It is distinct from CVE-2009-1535.
Description
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote authentication bypass with possible file read/write on an internet-facing service, plus a very high EPSS score, warrants critical priority despite no KEV listing.
What it is
The WebDAV extension in Microsoft IIS 5.0 on Windows 2000 SP4 fails to properly decode URLs, letting a remote attacker bypass authentication with a crafted HTTP request. Because the flaw defeats the authentication check itself, it undermines the primary access control protecting WebDAV resources. It is distinct from CVE-2009-1535.
Impact
An attacker can bypass authentication and possibly read or create files on the affected server, gaining unauthorized access to WebDAV-managed content.
Attack surface
Reachable over the network via HTTP against the IIS 5.0 WebDAV extension; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.98447, 99.9th percentile), indicating strong predicted exploitation likelihood; references are advisories and the MS09-020 patch, with no public exploit tag.
What to do
- Apply Microsoft security bulletin MS09-020 (the vendor patch) as the first action.
- If IIS 5.0 WebDAV is not required, disable or remove the WebDAV extension.
- Restrict network access to WebDAV endpoints to trusted hosts only.
- Upgrade off Windows 2000 SP4 and IIS 5.0, which are long past end of support.
Detection
- Inspect web server logs for crafted or malformed URL requests to WebDAV paths that return success without prior authentication.
- Alert on HTTP requests to WebDAV methods or paths that bypass expected 401 authentication responses.
- Monitor for unexpected file creation or modification in WebDAV-enabled directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1122 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1122), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.