CVE-2000-0256: Buffer Overflow
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Office FrontPage Server Extensions (FrontPage 97 and 98 Server Extensions)from your environment.Uninstall or remove FrontPage 97/98 Server Extensions from affected web servers to eliminate the vulnerable components (htimage.exe and Imagemap.exe).
- Configuration
Disable or remove execution mappings for htimage.exe and Imagemap.exe in the web server and FrontPage Server Extensions configuration so the server-side image map components cannot be invoked.
FrontPage Server Extensions (Server-Side Image Map Components) htimage.exe / Imagemap.exe execution = disabled - Compensating control
Block or restrict HTTP access to htimage.exe and Imagemap.exe at the network perimeter or on the web server (firewall, proxy, or web server access control lists); allow access only from trusted management IPs if required.
- Compensating control
Isolate or restrict network access to Microsoft Windows NT hosts and Microsoft Personal Web Server instances that host the vulnerable FrontPage Server Extensions until the vulnerable components are removed or disabled.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0256?
CVE-2000-0256 is classified as a critical vulnerability due to potential buffer overflow attacks.
How do I fix CVE-2000-0256?
To fix CVE-2000-0256, update to the latest patches provided by Microsoft for FrontPage Server Extensions.
What systems are affected by CVE-2000-0256?
CVE-2000-0256 affects Microsoft FrontPage 97 and 98 Server Extensions, Microsoft Personal Web Server 2.0, and Microsoft Windows NT 4.0.
What type of vulnerability is CVE-2000-0256?
CVE-2000-0256 is a buffer overflow vulnerability that can be exploited through specific server-side components.
What are the implications of CVE-2000-0256?
Exploitation of CVE-2000-0256 can allow unauthorized access and manipulation of server functionalities.