Search

published date: November 14, 2000

CVE-2000-0858 : Denial of Service Vulnerability

Description

Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.

Product(s):

  • Microsoft IIS 4.0
  • Microsoft Internet Information Server 4.0 Far East Edition
  • Microsoft Internet Information Server 4.0 Alpha
  • Microsoft IIS 4.0 Japanese
  • Microsoft IIS 4.0 Korean
  • Microsoft IIS 4.0 Chinese

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2000-0858, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2000-0858 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?