SP question : Microsoft IIS ISAPI Extension Enumerate Root Web Server Directory Vulnerability

Cantor, Scott cantor.2 at osu.edu
Wed Jun 4 14:15:42 UTC 2025


> Are you referring to "Modern-ish IIS module" as "Configuring
> the new plugin" documented in the wiki page titled "Upgrading
> Older ISAPI Configuration"?

An installation of the SP in recent memory doesn't involve anything like that, but something older would have to be migrated, yes. Upgrading the SP doesn't change how things are configured, and until the rewrite is done, the old filter will keep getting packaged and included. But it hasn't neen supported officially since 3.0 came out.

> Is this an out-of-the-box configuration or a follow-up task after
> the installation by using this command

That doesn't remove all the older bits, it just adds the new module by hand.

-- Scott




More information about the users mailing list