CVE-2000-0256: Buffer Overflow

Published Apr 19, 2000
·
Updated

Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.

Affected Software

3 affected components
Microsoft Windows NT=4.0
Microsoft Personal Web Server=2.0
Microsoft FrontPage

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Microsoft Office FrontPage Server Extensions (FrontPage 97 and 98 Server Extensions) from your environment.

    Uninstall or remove FrontPage 97/98 Server Extensions from affected web servers to eliminate the vulnerable components (htimage.exe and Imagemap.exe).

  2. Configuration

    Disable or remove execution mappings for htimage.exe and Imagemap.exe in the web server and FrontPage Server Extensions configuration so the server-side image map components cannot be invoked.

    FrontPage Server Extensions (Server-Side Image Map Components) htimage.exe / Imagemap.exe execution = disabled
  3. Compensating control

    Block or restrict HTTP access to htimage.exe and Imagemap.exe at the network perimeter or on the web server (firewall, proxy, or web server access control lists); allow access only from trusted management IPs if required.

  4. Compensating control

    Isolate or restrict network access to Microsoft Windows NT hosts and Microsoft Personal Web Server instances that host the vulnerable FrontPage Server Extensions until the vulnerable components are removed or disabled.

Event History

Apr 19, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Apr 26, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0256?

CVE-2000-0256 is classified as a critical vulnerability due to potential buffer overflow attacks.

2

How do I fix CVE-2000-0256?

To fix CVE-2000-0256, update to the latest patches provided by Microsoft for FrontPage Server Extensions.

3

What systems are affected by CVE-2000-0256?

CVE-2000-0256 affects Microsoft FrontPage 97 and 98 Server Extensions, Microsoft Personal Web Server 2.0, and Microsoft Windows NT 4.0.

4

What type of vulnerability is CVE-2000-0256?

CVE-2000-0256 is a buffer overflow vulnerability that can be exploited through specific server-side components.

5

What are the implications of CVE-2000-0256?

Exploitation of CVE-2000-0256 can allow unauthorized access and manipulation of server functionalities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203