Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability

BID:4474

Info

Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability

Bugtraq ID: 4474
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Apr 10 2002 12:00AM
Updated: Apr 10 2002 12:00AM
Credit: Discovery of this issue is credited to Dave Aitel of @Stake and Peter Grundl of KPMG.
Vulnerable: Microsoft IIS 5.0
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server SP1
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional SP1
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server SP1
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000 Server
Microsoft IIS 4.0
+ Cisco Building Broadband Service Manager (BBSM) 5.0
+ Cisco Building Broadband Service Manager (BBSM) 5.0
+ Cisco Call Manager 3.0
+ Cisco Call Manager 3.0
+ Cisco Call Manager 2.0
+ Cisco Call Manager 2.0
+ Cisco Call Manager 1.0
+ Cisco Call Manager 1.0
+ Cisco ICS 7750
+ Cisco ICS 7750
+ Cisco IP/VC 3540 Video Rate Matching Module
+ Cisco IP/VC 3540 Video Rate Matching Module
+ Cisco Unity Server 2.4
+ Cisco Unity Server 2.4
+ Cisco Unity Server 2.3
+ Cisco Unity Server 2.3
+ Cisco Unity Server 2.2
+ Cisco Unity Server 2.2
+ Cisco Unity Server 2.0
+ Cisco Unity Server 2.0
+ Cisco uOne 4.0
+ Cisco uOne 4.0
+ Cisco uOne 3.0
+ Cisco uOne 3.0
+ Cisco uOne 2.0
+ Cisco uOne 2.0
+ Cisco uOne 1.0
+ Cisco uOne 1.0
+ Hancom Hancom Office 2007 0
+ Hancom Hancom Office 2007 0
+ Microsoft BackOffice 4.5
+ Microsoft BackOffice 4.5
+ Microsoft Windows NT 4.0 Option Pack
+ Microsoft Windows NT 4.0 Option Pack
Cisco Unity Server 2.4
Cisco Unity Server 2.3
Cisco Unity Server 2.2
Cisco Unity Server 2.1
Cisco Unity Server 2.0
Cisco Call Manager 3.2
+ Cisco VoIP Phone 7902G 0
+ Cisco VoIP Phone 7905G 0
+ Cisco VoIP Phone 7912G 0
Cisco Call Manager 3.1
Cisco Call Manager 3.0
Cisco Building Broadband Service Manager (BBSM) 5.1
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.3
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Not Vulnerable:

Exploit / POC

Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Microsoft IIS HTR ISAPI Extension Buffer Overflow Vulnerability

Solution:
Microsoft has released an IIS cumulative patch to address all these issues.

There are reports of problems with the fixes for users who are running Microsoft IIS Site Server. A hotfix to address problems caused as a side effect of installing the cumulative patch has apparently been released by Microsoft. Any users who have experienced difficulties as a result of installing the cumulative patch are advised to contact Microsoft support and request hotfix Q317815.

Users of Cisco Unity products and Cisco Building Broadband Service Manager 4.x/5.x are advised to apply Microsoft's cumulative patch.


Microsoft IIS 4.0

Microsoft IIS 5.0

Cisco Unity Server 2.0

Cisco Unity Server 2.1

Cisco Unity Server 2.2

Cisco Unity Server 2.3

Cisco Unity Server 2.4

Cisco Call Manager 3.0
  • Cisco win-OS-Upgrade.2000-1-3spA.exe


Cisco Call Manager 3.1
  • Cisco win-OS-Upgrade.2000-1-3spA.exe


Cisco Call Manager 3.2
  • Cisco win-OS-Upgrade.2000-1-3spA.exe


Cisco Building Broadband Service Manager (BBSM) 4.0.1

Cisco Building Broadband Service Manager (BBSM) 4.2

Cisco Building Broadband Service Manager (BBSM) 4.3

Cisco Building Broadband Service Manager (BBSM) 4.4

Cisco Building Broadband Service Manager (BBSM) 4.5

Cisco Building Broadband Service Manager (BBSM) 5.0

Cisco Building Broadband Service Manager (BBSM) 5.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report