Overview
A vulnerability exists in Microsoft IIS 5.0 running on Windows 2000 that allows a remote intruder to run arbitrary code on the victim machine.
Description
Windows 2000 includes support for the Internet Printing Protocol (IPP) via an ISAPI extension. According to Microsoft, this extension is installed by default on all Windows 2000 systems, but is only accesible through IIS 5.0. The IPP ISAPI extension contains a buffer overflow that could be used by an attacker to execute arbitrary code in the Local System security context, essentially giving the attacker compete control of the system. For more information, see MS01-023 and the eEye Digital Security bulletin. |
Impact
Remote intruders can execute arbitrary code in the Local System security context. |
Solution
Install the patch as described in http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29321 |
One workaround is to remove the ISAPI Internet Printing extension by following these steps:
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/bulletin/MS01-023.asp
- http://www.eeye.com/html/Research/Advisories/AD20010501.html
- http://www.microsoft.com/technet/security/iis5chk.asp
- http://www.microsoft.com/technet/security/tools.asp
- http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29321
- http://www.securityfocus.com/bid/2674
Acknowledgements
This document was written by Shawn V Hernan.
Other Information
CVE IDs: | CVE-2001-0241 |
CERT Advisory: | CA-2001-10 |
Severity Metric: | 54.00 |
Date Public: | 2001-05-01 |
Date First Published: | 2001-05-02 |
Date Last Updated: | 2001-06-26 03:04 UTC |
Document Revision: | 15 |