CVE Tools

Description

IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.

In plain language

AI Worth attention

If your business still runs Microsoft Internet Information Services (IIS) 4.0 or 5.0, a remote attacker may be able to access files that should be blocked by web permissions when the parent folder permissions are looser than they should be—this is worth acting on, especially if the web server is reachable from the internet.

Executive summary

In IIS 4.0 and 5.0, improper permission checks tied to parent folder settings can let unauthenticated remote attackers bypass web file access restrictions via flawed file permission canonicalization.

If affected, business impact
Unauthorized access to restricted filesSensitive data exposureWebsite content or configuration leakageIncreased chance of further compromise

What to do now

  1. Confirm whether you run Microsoft Internet Information Services (IIS) 4.0 or 5.0 (not just “IIS in general”) on any internet-facing web server.
  2. Check the permissions on the parent folders of any files you intend to protect; look for cases where parent folders are more permissive than the specific files/directories you meant to lock down.
  3. Tighten permissions so parent folders are not “looser” than the restricted files they contain (use least-privilege on parent folders).
  4. Review the vendor/industry guidance referenced as a remediation for this issue and apply any available security update or configuration change for IIS 4.0/5.0.
  5. If you cannot update quickly, reduce exposure by restricting network access to the server (for example, allow only necessary IPs) and ensure only the intended site paths are reachable.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LAu:NC:PI:PA:N
Exploitability
AV:NAccess Vector
Network
AC:LAccess Complexity
Low
Au:NAuthentication
None
Impact
C:PConfidentiality
Partial
I:PIntegrity
Partial
A:NAvailability
None

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

Official Patch Available

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2000-0770 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows