Overview
A vulnerability exists in the Indexing services used by Microsoft IIS 4.0 and IIS 5.0 running on Windows NT, Windows 2000, and beta versions of Windows XP. Exploitations of this vulnerability allows a remote intruder to run arbitrary code on the victim machine.
Description
There is a remotely exploitable buffer overflow in the ISAPI (Indexing Service Application Programming Interface) extension (IDQ.DLL) installed with most versions of IIS 4.0 and 5.0. This affects Windows NT 4.0, Windows 2000 (Server and Professional), Windows 2000 Datacenter OEM distributions, Indexing Server 2.0, and the Indexing Services on all Windows 2000 platforms; however, not all of these instances are vulnerable by default. The beta versions of Windows XP are vulnerable by default. |
Impact
Remote intruders can execute arbitrary code with SYSTEM privileges in the Local System security context. |
Solution
Apply patches for vulnerable Windows NT 4.0 and Windows 2000 systems: |
WorkaroundsAll affected versions of IIS/Indexing Services can be protected against exploits of this vulnerbility by removing script mappings for for Internet Data Administration (.ida) and Internet Data Query (.idq) files. However, Microsoft makes no guarantees such mappings will not be recreated when installing other related software components. Users of beta copies of Windows XP should upgrade to a newer version of the software when it becomes available. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/bulletin/ms01-033.asp
- http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
- http://support.microsoft.com/support/kb/articles/Q300/9/72.ASP
- http://www.eeye.com/html/Research/Advisories/AD20010618.html
- http://www.microsoft.com/technet/security/iis5chk.asp
- http://www.microsoft.com/technet/security/tools.asp
- http://www.securityfocus.com/bid/2880
Acknowledgements
Our thanks to Microsoft Corporation and eEye Digital Security for contributing technical information about this vulnerability.
This document was written by Jeffrey S. Havrilla
Other Information
CVE IDs: | CVE-2001-0500 |
CERT Advisory: | CA-2001-13 |
Severity Metric: | 69.30 |
Date Public: | 2001-06-18 |
Date First Published: | 2001-06-19 |
Date Last Updated: | 2001-08-16 14:28 UTC |
Document Revision: | 30 |