Description
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2006-2702)
Apache HTTP Server Other Vulnerability (CVE-2021-33193)
IBM RTC Improper Neutralization of HTTP Headers for Scripting Syntax Vulnerability (CVE-2024-51454)
OpenVPN AS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2061)
Liferay DXP Incorrect Authorization Vulnerability (CVE-2025-3586)