Overview
Microsoft FrontPage Server Extensions contains a vulnerability that allows remote attackers to execute arbitrary code with local system privileges.
Description
Microsoft FrontPage Server Extensions (FPSE) is an optional set of tools that adds functionality to a web site. This functionality includes remote server administration, content updates, and a variety of site-specific tools such as searching support and form handling. According to MS03-051, FPSE is installed by default on Internet Information Server (IIS) 4.0, 5.0, and 5.1. The FPSE contains a buffer overflow vulnerability in its support of remote debugging. This vulnerability can be exploited by an unauthenticated remote attacker and allows arbitrary code to be executed with local system privileges. |
Impact
This vulnerability allows unauthenticated remote attackers to execute arbitrary code with local system privileges. |
Solution
Apply a patch from Microsoft |
Disable FrontPage Server Extensions |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported to Microsoft by Brett More of Security-Assessment.com.
This document was written by Jeffrey P. Lanza and is based upon information provided by Microsoft.
Other Information
CVE IDs: | CVE-2003-0822 |
Severity Metric: | 52.31 |
Date Public: | 2003-11-11 |
Date First Published: | 2003-11-12 |
Date Last Updated: | 2003-11-14 19:39 UTC |
Document Revision: | 18 |