Lucene search

K
saintSAINT CorporationSAINT:FDA4CD97FF94DFA307E7C96A19C2B7C6
HistoryFeb 08, 2006 - 12:00 a.m.

Microsoft IIS 5.0 printer ISAPI extension buffer overflow

2006-02-0800:00:00
SAINT Corporation
my.saintcorporation.com
18

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.954 High

EPSS

Percentile

99.4%

Added: 02/08/2006
CVE: CVE-2001-0241
BID: 2674
OSVDB: 3323

Background

Microsoft IIS web servers include ISAPI extensions which are invoked in the server process to handle requests of a given type.

Problem

The ISAPI extension which handles requests for file names ending in **.printer** is affected by a buffer overflow which could allow remote attackers to execute arbitrary commands.

Resolution

Install Windows 2000 Service Pack 2.

References

<http://www.microsoft.com/technet/security/bulletin/ms01-023.mspx&gt;
<http://archives.neohapsis.com/archives/bugtraq/2001-05/0006.html&gt;

Platforms

Windows

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.954 High

EPSS

Percentile

99.4%