Microsoft IIS HTR ISAPI ISM.DLL extension buffer overflow

iis-htr-isapi-bo (8799) The risk level is classified as HighHigh Risk

Description:

Microsoft Internet Information Server (IIS) is vulnerable to a buffer overflow in the ISAPI (Internet Services Application Programming Interface) ISM.DLL extension, which is used to implement HTR scripting. By sending a series of malformed HTR script requests to the Web server, a remote attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the IIS service to fail.The ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided. This may allow remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.

Platforms Affected:

  • Microsoft, IIS 4.0
  • Microsoft, IIS 5.0

Remedy:

For Virtual Patch:

Enable the following checks in the ISS Protection Platform:
HTTP_IIS_htr_isapi

Block or restrict the following in the ISS Protection Platform as appropriate to the environment:
Port 80

For Manual Protection:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS02-062. See References.

Note: Microsoft originally provided a patch for this vulnerability in MS02-018, but it was superseded by the patch released with MS02-062, and then superseded by the patch released with MS03-018. See References.

Note: This vulnerability also affects several Cisco products that use IIS. For affected products and upgrade or patch information refer to Cisco Security Advisory: Microsoft IIS Vulnerabilities in Cisco Products - MS02-018. See References.

Consequences:

Gain Access

References:

Reported:

Apr 10, 2002

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page