CVE-2000-0114: Medium severity Microsoft Internet Information Server vulnerability

Published Feb 2, 2000
·
Updated

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /vtibin/ virtual directory.

Affected Software

2 affected components
Microsoft Internet Information Server=3.0
Microsoft Internet Information Server=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove FrontPage Server Extensions from your environment.

    Uninstall or remove FrontPage Server Extensions from the IIS server if the feature is not required.

  2. Configuration

    Disable FrontPage Server Extensions in IIS Manager (or via server roles/feature removal) to prevent disclosure via shtml.dll in the /_vti_bin/ virtual directory.

    Microsoft Internet Information Services (FrontPage Server Extensions) FrontPage Server Extensions = disabled
  3. Configuration

    Remove or disable the shtml.dll ISAPI/handler mapping and block HTTP POST requests to shtml.dll in the /_vti_bin/ virtual directory to prevent RPC POST-based disclosure.

    IIS / _vti_bin/ virtual directory Access to shtml.dll = disabled
  4. Compensating control

    Restrict access to the /_vti_bin/ virtual directory and shtml.dll to trusted IP addresses or management networks using firewall rules, network ACLs, or a web application firewall to prevent remote attackers from reaching the endpoint.

  5. Operational

    Change or audit the anonymous account used for IIS anonymous access (rename or replace the account), and review server logs for suspicious RPC POSTs to /_vti_bin/shtml.dll to detect possible exploitation.

Event History

Feb 2, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 8, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0114?

CVE-2000-0114 is considered a medium severity vulnerability as it can disclose sensitive information about the anonymous account.

2

How do I fix CVE-2000-0114?

To fix CVE-2000-0114, it's recommended to disable the Frontpage Server Extensions or apply security patches provided by Microsoft.

3

Who is affected by CVE-2000-0114?

CVE-2000-0114 affects users of Microsoft Internet Information Server versions 3.0 and 4.0 with Frontpage Server Extensions enabled.

4

What does CVE-2000-0114 exploit?

CVE-2000-0114 exploits a vulnerability in the RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.

5

Can CVE-2000-0114 be exploited remotely?

Yes, CVE-2000-0114 can be exploited remotely by attackers to determine the name of the anonymous account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203