← Vulnerability feed

Vulnerability record · CVE-2009-2521 · published 4 September 2009

CVE-2009-2521: Microsoft IIS FTP Service stack consumption denial of service

Microsoft · Internet Information Services

The FTP Service in Microsoft IIS 5.0 through 7.0 mishandles a recursive list (ls -R) command containing a wildcard that references a subdirectory followed by a dot-dot sequence, exhausting the stack. A remote authenticated FTP user can crash the daemon, taking the FTP service offline. The record gives no affected version detail beyond the IIS 5.0-7.0 range and no CVSS v3 score.

5.0 CVSS 2.0 Medium EPSS 82% · top 0.3% CWE-400 · Uncontrolled resource consumption
5.0CVSS 2.0 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw only causes a denial of service and requires authenticated FTP access, but the affected IIS versions are legacy and EPSS is very high.

What it is

The FTP Service in Microsoft IIS 5.0 through 7.0 mishandles a recursive list (ls -R) command containing a wildcard that references a subdirectory followed by a dot-dot sequence, exhausting the stack. A remote authenticated FTP user can crash the daemon, taking the FTP service offline. The record gives no affected version detail beyond the IIS 5.0-7.0 range and no CVSS v3 score.

Impact

An attacker with valid FTP credentials can cause a denial of service by crashing the IIS FTP daemon, interrupting FTP availability for all users on that host. There is no confidentiality or integrity impact; the CVSS v2 vector rates availability impact as partial.

Attack surface

Reached over the network through the FTP service (AV:N, AC:L) by a remote authenticated user; the description states authentication is required, and no user interaction is indicated. The trigger is a crafted ls -R command with a wildcard subdirectory reference followed by dot-dot.

Exploitation

Not listed in CISA KEV and no ransomware use is documented; EPSS is high (0.82265, 99.6th percentile), and references include a vendor patch bulletin (MS09-053) plus US-CERT and OVAL advisories, but no public exploit tag is present in the record.

What to do

  • Apply Microsoft security bulletin MS09-053 (KB975191) to affected IIS FTP installations.
  • Restrict FTP access to trusted accounts and disable or block anonymous FTP where not required.
  • Limit FTP directory listing recursion and monitor for repeated ls -R commands with wildcard and dot-dot patterns.
  • If the FTP service is not needed, disable it or migrate off IIS 5.0-7.0 FTP to a supported platform.

Detection

  • Alert on FTP commands containing 'ls -R' combined with wildcard characters and '..' sequences in server or FTP logs.
  • Monitor for unexpected IIS FTP service crashes or restarts in Windows event logs.
  • Baseline and watch for spikes in recursive directory listing commands from a single authenticated FTP account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-2521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7269IIS 6.0 WebDAV ScStoragePathFromUrl buffer overflow enables remote code executionA buffer overflow in the ScStoragePathFromUrl function of the WebDAV service in IIS 6.0 on Windows Server 2003 R2 allows remote code execution via a …KEVEPSS 100%analysed10.0CVE-2010-3972Microsoft IIS FTP Service heap buffer overflow via crafted FTP commandA heap-based buffer overflow exists in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 as shipped w…EPSS 95%analysed10.0CVE-2008-4301Microsoft internet information services vulnerabilityA certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argum…EPSS 17%10.0CVE-2007-2815IIS 5.0 webhits.dll hit-highlighting authentication bypassThe hit-highlighting feature in webhits.dll on Microsoft IIS 5.0 relies only on Windows NT ACLs, so it fails to enforce NTLM or basic authentication.…EPSS 73%analysed10.0CVE-2003-0224Microsoft internet information services vulnerabilityBuffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a…EPSS 18%10.0CVE-1999-0233Microsoft internet information services vulnerabilityIIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.EPSS 16%9.3CVE-2010-2730Microsoft internet information services memory buffer overflow vulnerabilityBuffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via …EPSS 33%9.0CVE-2008-1446Microsoft IIS IPP ISAPI integer overflow enables remote code executionThe Internet Printing Protocol (IPP) ISAPI extension in Microsoft IIS 5.0 through 7.0 contains an integer overflow that can be triggered by a crafted…EPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2009-2521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.