modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Mar 5, 2010 |
| Apache Httpd 2_2_x Mod_isapi Module Unload Flaw | — | — | Aug 16, 2010 | Mar 5, 2010 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-utilsUpgrade apache2-docUpgrade apache2-develUpgrade apache2Upgrade apache2-example-pagesUpgrade apache2-worker | Aug 9, 2024 | Mar 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub