CVE-2000-0457: High severity Microsoft Internet Information Services vulnerability

Published May 11, 2000
·
Updated

ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

Affected Software

2 affected components
Microsoft Internet Information Services=5.0
Microsoft Internet Information Server=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Microsoft Internet Information Services (IIS) - ISM.DLL from your environment.

    Unregister or remove ISM.DLL if the .htr processing functionality is not required by your applications

  2. Configuration

    Disable or remove the ISAPI extension mapping that processes .htr files with ISM.DLL (unregister or disable ISM.DLL handling of .htr requests)

    Microsoft Internet Information Services (IIS) - ISM.DLL / .htr mapping ISAPI extension mapping for .htr (ISM.DLL) = disabled
  3. Compensating control

    Configure perimeter controls (WAF, proxy or firewall) to block or drop HTTP requests for .htr files and to block requests containing long sequences of encoded spaces (%20) to prevent file fragment reading attempts

  4. Operational

    Monitor web server logs for requests for .htr files or requests containing many %20 sequences; investigate incidents and block or remediate offending sources

Event History

May 11, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0457?

CVE-2000-0457 is considered to have a high severity due to the potential for unauthorized file access.

2

How do I fix CVE-2000-0457?

To fix CVE-2000-0457, it is recommended to upgrade to a secure version of IIS or apply patches provided by Microsoft.

3

What is the impact of CVE-2000-0457?

The impact of CVE-2000-0457 is that attackers can read sensitive files on the server by exploiting the .htr file fragment reading vulnerability.

4

Which versions are affected by CVE-2000-0457?

CVE-2000-0457 affects Microsoft Internet Information Server versions 4.0 and 5.0.

5

Can CVE-2000-0457 be exploited remotely?

Yes, CVE-2000-0457 can be exploited remotely, allowing attackers to access files without authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203