AI Score
Confidence
Low
EPSS
Percentile
82.7%
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the βEscape Character Parsingβ vulnerability.
support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246401
www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt
docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-061