CVE-2000-0304: Medium severity Microsoft Internet Information Services vulnerability
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IISADMPWD virtual directoryfrom your environment.Uninstall or delete the IISADMPWD virtual directory from affected Microsoft IIS 4.0 and 5.0 servers if it is not required.
- Configuration
Disable the IISADMPWD virtual directory in IIS Manager (or remove its script mappings) to prevent handling of malformed .HTR requests.
Microsoft Internet Information Services (IIS) - IISADMPWD virtual directory virtual_directory_enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0304?
CVE-2000-0304 has been classified as a denial of service vulnerability which can disrupt service availability.
How do I fix CVE-2000-0304?
To fix CVE-2000-0304, you should remove the IISADMPWD virtual directory or apply relevant patches and updates from Microsoft.
Which versions of IIS are impacted by CVE-2000-0304?
CVE-2000-0304 affects Microsoft Internet Information Server versions 4.0 and 5.0.
What type of attack does CVE-2000-0304 enable?
CVE-2000-0304 enables a remote attacker to execute a denial of service attack by sending a malformed request.
Is CVE-2000-0304 still a concern for users of IIS?
Yes, users of affected versions of IIS should take immediate action to mitigate the risks associated with CVE-2000-0304.