Microsoft Internet Information Server 5.0 Patch: Unchecked Buffer in ISAPI Extension

This update resolves the "Unchecked Buffer in ISAPI Extension Could Enable Compromise of IIS 5.0 Server" security vulnerability in Windows 2000 and is discussed in Microsoft Security Bulletin MS01-023. Download now to prevent a malicious user from taking control of your Web server. The Internet Printing ISAPI (Internet Services Application Programming Interface) extension for Windows 2000 has an unchecked buffer (a temporary data storage area that has a limited capacity) in the code that processes users' print requests. A specifically malformed request from a malicious user can cause the buffer to overflow. Doing so grants the malicious user Local System privileges, allowing him to take complete control of the Web server. This update eliminates the vulnerability by ensuring that the ISAPI extension checks input correctly. Note Although the affected component is not part of Internet Information Services (IIS) 5.0, the vulnerability is present only when IIS 5.0 is running.
PriceUSD0
LicenseFree
File Size258.09 kB
VersionUpdate
Operating System Windows 98 Windows XP Windows 2000 Windows
System Requirements
  • Windows NT 4 SP 6
  • Windows 2003 SP 1
  • Windows XP AMD 64-bit
  • Windows XP 64-bit SP 1
  • Windows NT 4 SP 2
  • Windows 2000 SP 1
  • Windows 2003 64-bit
  • Windows 2003 AMD 64-bit
  • Windows XP 64-bit SP 2
  • Windows NT 4 SP 3
  • Windows 2000 SP 2
  • Windows Server 2003 x64 R2
  • Windows 2000
  • Windows 2003 64-bit SP 1
  • Windows Vista AMD 64-bit
  • Windows XP Itanium 64-bit
  • Windows NT 4 SP 4
  • Windows 2000 SP 3
  • Windows NT 4
  • Windows XP 32-bit
  • Windows XP SP 1
  • Windows Server 2003 x86 R2
  • Windows ME
  • Windows 2003 Itanium 64-bit
  • Windows NT 4 SP 5
  • Windows 2000 SP 4
  • Windows Vista 32-bit
  • Windows XP 64-bit
  • Windows NT 4 SP 1
  • Windows Server 2008 x64
  • Windows NT 3
  • Windows Server 2008 x86
  • Windows XP
  • Windows Server 2008
  • Windows 2003
  • Windows Vista Itanium 64-bit
  • Windows XP Itanium 64-bit SP 1
  • Windows 2003 32-bit
  • Windows XP Itanium 64-bit SP 2
  • Windows XP SP 2
  • Windows 95
  • Windows 98
  • Windows Vista
  • Windows NT
  • Windows 2003 Itanium 64-bit SP 1
  • Windows XP Pro