Vulnerability record · CVE-2009-2521 · published 4 September 2009
CVE-2009-2521: Microsoft IIS FTP Service stack consumption denial of service
Microsoft · Internet Information Services
The FTP Service in Microsoft IIS 5.0 through 7.0 mishandles a recursive list (ls -R) command containing a wildcard that references a subdirectory followed by a dot-dot sequence, exhausting the stack. A remote authenticated FTP user can crash the daemon, taking the FTP service offline. The record gives no affected version detail beyond the IIS 5.0-7.0 range and no CVSS v3 score.
Description
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw only causes a denial of service and requires authenticated FTP access, but the affected IIS versions are legacy and EPSS is very high.
What it is
The FTP Service in Microsoft IIS 5.0 through 7.0 mishandles a recursive list (ls -R) command containing a wildcard that references a subdirectory followed by a dot-dot sequence, exhausting the stack. A remote authenticated FTP user can crash the daemon, taking the FTP service offline. The record gives no affected version detail beyond the IIS 5.0-7.0 range and no CVSS v3 score.
Impact
An attacker with valid FTP credentials can cause a denial of service by crashing the IIS FTP daemon, interrupting FTP availability for all users on that host. There is no confidentiality or integrity impact; the CVSS v2 vector rates availability impact as partial.
Attack surface
Reached over the network through the FTP service (AV:N, AC:L) by a remote authenticated user; the description states authentication is required, and no user interaction is indicated. The trigger is a crafted ls -R command with a wildcard subdirectory reference followed by dot-dot.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is high (0.82265, 99.6th percentile), and references include a vendor patch bulletin (MS09-053) plus US-CERT and OVAL advisories, but no public exploit tag is present in the record.
What to do
- Apply Microsoft security bulletin MS09-053 (KB975191) to affected IIS FTP installations.
- Restrict FTP access to trusted accounts and disable or block anonymous FTP where not required.
- Limit FTP directory listing recursion and monitor for repeated ls -R commands with wildcard and dot-dot patterns.
- If the FTP service is not needed, disable it or migrate off IIS 5.0-7.0 FTP to a supported platform.
Detection
- Alert on FTP commands containing 'ls -R' combined with wildcard characters and '..' sequences in server or FTP logs.
- Monitor for unexpected IIS FTP service crashes or restarts in Windows event logs.
- Baseline and watch for spikes in recursive directory listing commands from a single authenticated FTP account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0040.html | Broken Link |
| http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ975191 | |
| http://www.us-cert.gov/cas/techalerts/TA09-286A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-053 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6508 | Third Party Advisory |
| http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0040.html | Broken Link |
| http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ975191 | |
| http://www.us-cert.gov/cas/techalerts/TA09-286A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-053 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6508 | Third Party Advisory |
Track CVE-2009-2521 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.