Back
CVE-2000-0770
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.
Published: Oct 20, 2000
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_information_server | 4.0 |
| microsoft | internet_information_services | 5.0 |
GitHub Security Advisory GHSA-8wcg-8pwm-v3gc
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent...
References (4)
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
14.19%
Top 4% most likely to be exploited
Threat Score
29.9 / 100
Data Sources
NVD
EPSS
GitHub