Vulnerability record · CVE-2009-1536 · published 12 August 2009
CVE-2009-1536: ASP.NET request scheduling flaw allows unauthenticated daemon outage
Microsoft · .Net Framework
ASP.NET in Microsoft .NET Framework 2.0 SP1/SP2 and 3.5 Gold/SP1 fails to properly manage request scheduling when ASP 2.0 runs in integrated mode on IIS 7.0. A series of crafted HTTP requests can exhaust the request pipeline and take the daemon down, causing a denial of service. The record does not list specific affected build numbers beyond the framework service pack levels named in the description.
Description
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
AV:N/AC:H/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is an unauthenticated remote denial of service on widely deployed legacy ASP.NET/IIS 7.0, but CVSS rates it low severity and no confirmed exploitation is recorded.
What it is
ASP.NET in Microsoft .NET Framework 2.0 SP1/SP2 and 3.5 Gold/SP1 fails to properly manage request scheduling when ASP 2.0 runs in integrated mode on IIS 7.0. A series of crafted HTTP requests can exhaust the request pipeline and take the daemon down, causing a denial of service. The record does not list specific affected build numbers beyond the framework service pack levels named in the description.
Impact
An unauthenticated remote attacker can cause a denial of service, taking the ASP.NET worker process offline and making hosted web applications unavailable. No data confidentiality or integrity impact is described; the effect is availability loss only.
Attack surface
Reachable over the network via HTTP against an IIS 7.0 server running ASP.NET in integrated pipeline mode with ASP 2.0. No authentication or user interaction is required, though the CVSS vector rates attack complexity as high.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is recorded in this entry. EPSS is 0.513 (98.9th percentile), indicating a high modeled likelihood of exploitation activity, but the record provides no confirmed in-the-wild evidence.
What to do
- Apply the Microsoft security update referenced in MS09-036 (the vendor advisory and patch references in this record).
- If patching cannot be done immediately, switch the affected application pool from integrated mode to classic ASP.NET pipeline mode where operationally feasible.
- Restrict or rate-limit inbound HTTP traffic to affected IIS 7.0 endpoints at the reverse proxy or WAF layer.
- Monitor worker process recycling and app pool crashes to catch recurrence after mitigation.
- Retire or isolate end-of-life .NET Framework 2.0/3.5 and IIS 7.0 hosts that cannot be patched.
Detection
- Alert on repeated ASP.NET worker process crashes or unexpected app pool recycles on IIS 7.0 hosts.
- Baseline normal request rates per client and flag bursts of malformed or high-frequency HTTP requests to ASP.NET endpoints.
- Correlate Windows Application and IIS logs for request-scheduling errors preceding daemon outages.
- Review WAF logs for repeated requests matching the crafted-request pattern described in the vendor advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1536 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1536), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.