MS11-100 DoS PoC exploit published

Published: 2012-01-09. Last Updated: 2012-01-09 19:21:27 UTC
by Manuel Humberto Santander Pelaez (Version: 1)
4 comment(s)

If you have not patched yet for vulnerability MS11-100 you might want to do it ASAP, because the DoS PoC exploit for this vulnerability has been published two days ago.

More information about the vulnerability and patches at

Manuel Humberto Santander Peláez
SANS Internet Storm Center - Handler
Twitter: @manuelsantander
e-mail: msantand at isc dot sans dot org



4 comment(s)


Can you please provide some references for your statement? I have found *nothing* except for a lot of references to this post. My employer usually requires more than a blog post to change a decisions they've already made after a risk analysis.

though I have not tried it.
We have posted ModSecurity mitigation options -

This is useful if you have front-ended your web app servers with a ModSecurity reverse proxy.
@Ryan: thanks for your work on the ModSecurity rules and these additions in particular!

Diary Archives