CVE-2000-0408
published 2000-05-11CVE-2000-0408: IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
55.86%
98.9th percentile
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for abnormally long URLs containing a large number of file extension sequences (e.g., repeated dot-separated segments) in IIS HTTP access logs, which is the hallmark of this DoS attack. ↗
- →Monitor IIS 4.0/5.0 host CPU usage for sudden spikes to 100% correlated with inbound HTTP requests containing malformed extension data, as the vulnerability causes CPU exhaustion until the URL is fully processed. ↗
- ·Affected versions are IIS 4.0 and 5.0 only; the DoS condition requires restarting the IIS application or waiting for the malformed URL to finish processing before normal service resumes. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://www.microsoft.com/technet/support/kb.asp?ID=260205http://www.securityfocus.com/bid/1190http://www.ussrback.com/labs40.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-030http://www.microsoft.com/technet/support/kb.asp?ID=260205http://www.securityfocus.com/bid/1190http://www.ussrback.com/labs40.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-030
2000-05-11
Published