The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
Use CWE-287, Microsoft vendor hub and Internet Information Services product page to widen CVE-2009-1122 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-7269, CVE-2010-3972 and CVE-2010-2730 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.