Skip to main content

CVE-2009-1535

CVSS Score Not Available
91.83%
HIGH RiskEPSS (100th percentile)

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.

Published: 6/10/2009
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

91.83%HIGH Exploitation Risk
100th percentile

This vulnerability has a 91.83% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.