SP question : Microsoft IIS ISAPI Extension Enumerate Root Web Server Directory Vulnerability

Lee, Dong DLee at umaryland.edu
Tue Jun 3 18:32:31 UTC 2025


Good afternoon,


Rapid7 reported a vulnerability in Microsoft IIS, identified as the "ISAPI Extension Enumerate Root Web Server Directory Vulnerability," which may allow unauthorized directory enumeration.



The report suggests remediating a vulnerability by enabling ISAPI mappings in IIS, specifically by navigating to Edit -> Request Restrictions and checking "Invoke handler only if request is mapped to: File." I researched the impact of this change and found that it may negatively affect the Shibboleth Service Provider (SP) because it relies on virtual paths (e.g., /Shibboleth.sso/Login) rather than physical files. However, I could not confirm this information. Can you validate whether this is correct? If true, what would be a suitable solution to address the vulnerability while maintaining SP functionality?


Thank you,
Dong Lee

Identity Management & System Integration
Center for Information Technology Services
University of Maryland, Baltimore
410-706-3027
dlee at umaryland.edu<mailto:dlee at umaryland.edu>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250603/377b3974/attachment.htm>


More information about the users mailing list