vendor:
Windows Index Server, Windows Indexing Service
by:
mat@hacksware.com, mat@monkey.org
7.5
CVSS
HIGH
Buffer Overflow
Not mentioned
CWE
Product Name: Windows Index Server, Windows Indexing Service
Affected Version From: Windows NT 4.0 Option Pack, Windows 2000
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: o:microsoft:windows_nt:4.0, cpe:/o:microsoft:windows:2000
Platforms Tested: Not mentioned
Not mentioned
Windows Index Server and Indexing Service idq.dll ISAPI Extension Buffer Overflow Vulnerability
A maliciously crafted request could allow arbitrary code to run on the host in the Local System context. This vulnerability is currently being exploited by the 'Code Red' worm.
Mitigation:
Patch the vulnerability or disable the affected service. Ensure that the system is updated with the latest security patches.