Vulnerability record · CVE-2019-17181 · published 28 October 2019
CVE-2019-17181: IntraSrv HTTP request SEH buffer overflow allows remote compromise
IIntrasrv Project · Intrasrv
IntraSrv 1.0 (2007-06-03) contains a remote SEH-based stack buffer overflow reachable through a crafted HTTP GET or HEAD request. Successful exploitation can compromise the hosting system, and the flaw carries a CVSS 3.1 base score of 9.8 (critical). The product is an old, apparently unsupported web server, so patching options are likely limited.
Description
A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and public exploit references make this a critical exposure for any host still running IntraSrv.
What it is
IntraSrv 1.0 (2007-06-03) contains a remote SEH-based stack buffer overflow reachable through a crafted HTTP GET or HEAD request. Successful exploitation can compromise the hosting system, and the flaw carries a CVSS 3.1 base score of 9.8 (critical). The product is an old, apparently unsupported web server, so patching options are likely limited.
Impact
An unauthenticated remote attacker can execute code in the context of the IntraSrv service, leading to full compromise of the hosting system (high confidentiality, integrity and availability impact per the CVSS vector).
Attack surface
Reachable over the network via the HTTP service; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required. Any host exposing IntraSrv on a reachable port is exposed.
Exploitation
Not listed in CISA KEV, but EPSS 30-day probability is 0.487 (98.8th percentile) and both reference URLs are tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Apply any vendor fix if one exists; the record names no patched version, so confirm with the vendor or project page first.
- If no patch is available, retire or replace IntraSrv, which dates to 2007 and is unlikely to be maintained.
- Restrict network access to the IntraSrv listener with firewall rules or a reverse proxy, allowing only trusted sources.
- Run the service under a low-privilege account and isolate it in a segmented host or container to limit post-exploitation reach.
- Monitor vendor and CVE channels for an updated fixed release, since none is identified in this record.
Detection
- Inspect HTTP server logs for GET or HEAD requests with unusually long or malformed URI/header fields targeting the IntraSrv listener.
- Alert on IntraSrv process crashes or restarts, which are consistent with SEH overflow attempts.
- Monitor for unexpected child processes or outbound connections originating from the IntraSrv host.
- Use network IDS signatures for known IntraSrv overflow exploit traffic if available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.leighb.com/intrasrv.htm | ExploitThird Party Advisory |
| https://cxsecurity.com/issue/WLB-2019100164 | ExploitThird Party Advisory |
| http://www.leighb.com/intrasrv.htm | ExploitThird Party Advisory |
| https://cxsecurity.com/issue/WLB-2019100164 | ExploitThird Party Advisory |
Track CVE-2019-17181 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17181), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.