Saturday, May 8, 2021

Microsoft Patches ‘Critical’ Windows 2000 Flaw

The Computer Emergency Response Team (CERT/CC) on Monday issued an advisory
for a buffer overflow vulnerability in Microsoft IIS 5.0 running on
Microsoft Windows 2000, warning sysadmins that an exploit is already
circulating.

Microsoft issued a “critical” rating on the flaw and issued a patch while warning that the
vulnerability may allow a remote attacker to run arbitrary code on an
infected machine.

“An exploit is publicly available for this vulnerability, which increases
the urgency that system administrators apply a patch,” the Center warned.
IIS 5.0 is installed and running by default on Microsoft Windows 2000 server
products.

CERT/CC said the unchecked buffer was detected in a Windows component of
the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol,
which is supported by Windows 2000. An attacker could send a specially
formed HTTP request to a machine running IIS, causing the server to fail or
to execute code of the attacker’s choice.

WebDAV uses IIS to pass requests to and from Windows 2000. Microsoft
explained that when IIS receives a WebDAV request, it typically processes
the request and then acts on it. However, if the request is formed in a
particular way, a buffer overrun can result because one of the Windows
components called by WebDAV does not correctly check parameters.

Similar articles

Latest Articles

Top 10 Professional Services...

These are some of the best PSA tools for organizations of all sizes. What Is Professional Services Automation Software? Professional services automation (PSA) software aims to...

What is Data Aggregation?

Data aggregation is the process where raw data is gathered and presented in a summarized format for statistical analysis. The data may be gathered...

Dell APEX: Our...

One of the missteps IBM made last century was collapsing their sales model, which was services based, to generate a short-term revenue spike. Up...

Companies that Scaled Technology...

NEW YORK — Companies that “doubled down” on their investment in mostly data-heavy technology during the COVID-19 pandemic have seen their revenue grow five...