vendor:
Windows Index Server and Windows Indexing Service
by:
Ps0 DtMF
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Windows Index Server and Windows Indexing Service
Affected Version From: Windows NT 4.0 Option Pack
Affected Version To: Windows 2000
Patch Exists: YES
Related CWE: CVE-2001-0333
CPE: o:microsoft:windows_2000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2001
DoS for isapi idq.dll unchecked buffer
Windows Index Server and Windows Indexing Service contain an unchecked buffer in the 'idq.dll' ISAPI extension. A maliciously crafted request could allow arbitrary code to run on the host in the Local System context. This vulnerability is currently being exploited by the 'Code Red' worm.
Mitigation:
Apply the patch provided by Microsoft or upgrade to a version of Windows that is not vulnerable.