Overview
Microsoft FrontPage Server Extensions contains a vulnerability that allows remote attackers to execute arbitrary code with local system privileges.
Description
Microsoft FrontPage Server Extensions (FPSE) is an optional set of tools that adds functionality to a web site. This functionality includes remote server administration, content updates, and a variety of site-specific tools such as searching support and form handling. According to MS03-051, FPSE is installed by default on Internet Information Server (IIS) 4.0, 5.0, and 5.1. The FPSE contains a buffer overflow vulnerability in its support of remote debugging. This vulnerability can be exploited by an unauthenticated remote attacker and allows arbitrary code to be executed with local system privileges. |
Impact
This vulnerability allows unauthenticated remote attackers to execute arbitrary code with local system privileges. |
Solution
Apply a patch from Microsoft |
Disable FrontPage Server Extensions |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
This vulnerability was reported to Microsoft by Brett More of Security-Assessment.com.
This document was written by Jeffrey P. Lanza and is based upon information provided by Microsoft.
Other Information
| CVE IDs: | CVE-2003-0822 |
| Severity Metric: | 52.31 |
| Date Public: | 2003-11-11 |
| Date First Published: | 2003-11-12 |
| Date Last Updated: | 2003-11-14 19:39 UTC |
| Document Revision: | 18 |