MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability

BID:2880

Info

MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability

Bugtraq ID: 2880
Class: Boundary Condition Error
CVE: CVE-2001-0500
Remote: Yes
Local: No
Published: Jun 18 2001 12:00AM
Updated: Nov 26 2009 09:05PM
Credit: Discovered by Riley Hassell of eEye Digital Security and posted in a Microsoft Security Bulletin MS01-033 on June 18, 2001.
Vulnerable: Microsoft Indexing Services for Windows 2000
+ Microsoft IIS 5.0
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
Microsoft Index Server 2.0
+ Microsoft IIS 4.0
+ Microsoft IIS 4.0
Cisco uOne Enterprise Edition
Cisco uOne 4.0
Cisco uOne 3.0
Cisco uOne 2.0
Cisco uOne 1.0
Cisco Unity Server 4.0
Cisco Unity Server 3.3
Cisco Unity Server 3.2
Cisco Unity Server 3.1
Cisco Unity Server 3.0
Cisco Unity Server 2.46
Cisco Unity Server 2.4
Cisco Unity Server 2.3
Cisco Unity Server 2.2
Cisco Unity Server 2.1
Cisco Unity Server 2.0
Cisco Unity Server
Cisco Trailhead
Cisco Media Blender
Cisco IP/VC 3540 Application Server
Cisco ICS Firmware 2.0
+ Cisco ICS 7750
Cisco ICS Firmware 1.0
+ Cisco ICS 7750
Cisco ICS 7750
Cisco Dynamic Content Adapter
Cisco Collaboration Server
Cisco Call Manager 4.0
Cisco Call Manager 3.3 (3)
Cisco Call Manager 3.3
Cisco Call Manager 3.2
+ Cisco VoIP Phone 7902G 0
+ Cisco VoIP Phone 7905G 0
+ Cisco VoIP Phone 7912G 0
Cisco Call Manager 3.1 (3a)
Cisco Call Manager 3.1 (2)
Cisco Call Manager 3.1
Cisco Call Manager 3.0
Cisco Call Manager 2.0
Cisco Call Manager 1.0
Cisco Call Manager
Cisco Building Broadband Service Manager (BBSM) 5.2
Cisco Building Broadband Service Manager (BBSM) 5.1
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.3
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Cisco Building Broadband Service Manager (BBSM) 3.0
Cisco Building Broadband Service Manager (BBSM) 2.5.1
Not Vulnerable:

Discussion

MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability

Windows Index Server ships with Windows NT 4.0 Option Pack; Windows Indexing Service ships with Windows 2000. An unchecked buffer resides in the 'idq.dll' ISAPI extension associated with each service. A maliciously crafted request could allow arbitrary code to run on the host in the Local System context.

Note that Index Server and Indexing Service do not need to be running for an attacker to exploit this issue. Since 'idq.dll' is installed by default when IIS is installed, IIS would need to be the only service running.

Note also that this vulnerability is currently being exploited by the 'Code Red' worm. In addition, all products that run affected versions of IIS are also vulnerable.

**UPDATE**: An aggressive worm that actively exploits this vulnerability is believed to be in the wild.

Exploit / POC

MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Exploits are available.

A Metasploit exploit module is also available.

Solution / Fix

MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability

Solution:
Microsoft has released a patch. Please see the references for details.

NOTE: Reports indicate that post-patch systems may be vulnerable to a denial of service; administrators are advised to reapply the newer patch if it is not installed and to remove the .ida/.idq mappings.

Microsoft has released the following tool that rectifies the damage caused by the 'Code Red II' worm:

http://www.microsoft.com/technet/itsolutions/security/tools/redfix.asp


Microsoft Index Server 2.0

Microsoft Indexing Services for Windows 2000

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report