CVE-2002-0072
published 2002-04-22CVE-2002-0072: The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
53.29%
98.9th percentile
The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products_ms02-018 | — | — |
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the w3svc.dll ISAPI filter in IIS 4.0, 5.0, and 5.1 — a remotely triggered null pointer dereference via an excessively long URL causes a denial of service (crash) ↗
- →Monitor inbound HTTP requests with abnormally long URLs targeting IIS servers running Front Page Server Extensions or ASP.NET; a crash/restart of w3svc (World Wide Web Publishing Service) following such a request is a strong indicator of exploitation ↗
- ·The vulnerability is in IIS itself (w3svc.dll ISAPI filter), not in any Cisco product or application installed on top of IIS; Cisco products are affected only because they run on Windows hosts with IIS enabled ↗
- ·Affected IIS versions are 4.0, 5.0, and 5.1 with Front Page Server Extensions or ASP.NET installed; detection rules should scope to these versions ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
vendor_cisco·2002-04-15
CVE-2002-0071 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
This advisory describes a vulnerability that affects Cisco products and
applications that are installed on Microsoft operating systems incorporating
the use of the Internet Information Server (IIS), and is based on the
vulnerability of IIS, not due to a defect of the Cisco product or application.
A number of vulnerabilities were discovered that enables an attacker to
execute arbitrary code or perform a denial of service against the server. These
vulnerabilities were discovered and publicly announced by Microsoft in their
Microsoft Security Bulletin MS02-018.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018.
Cisco
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
vendor_cisco
CVE-2002-0072 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
CVE-2002-0072: Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
This advisory describes a vulnerability that affects Cisco products and applications that are installed on Microsoft operating systems incorporating the use of the Internet Information Server (IIS), and is based on the vulnerability of IIS, not due to a defect of the Cisco product or application. A number of vulnerabilities were discovered that enables an attacker to execute arbitrary code or perform a denial of service against the server. These vulnerabilities were discovered and publicly announced by Microsoft in their Microsoft Security Bulletin MS02-018. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018 .
GHSA
GHSA-84f6-4j88-6cvc: The w3svc
ghsa_unreviewed·2022-04-30
CVE-2002-0072 [MEDIUM] GHSA-84f6-4j88-6cvc: The w3svc
The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=101853851025208&w=2http://www.cert.org/advisories/CA-2002-09.htmlhttp://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtmlhttp://www.iss.net/security_center/static/8800.phphttp://www.kb.cert.org/vuls/id/521059http://www.osvdb.org/3326http://www.securityfocus.com/bid/4479https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-018http://marc.info/?l=bugtraq&m=101853851025208&w=2http://www.cert.org/advisories/CA-2002-09.htmlhttp://www.cisco.com/warp/public/707/Microsoft-IIS-vulnerabilities-MS02-018.shtmlhttp://www.iss.net/security_center/static/8800.phphttp://www.kb.cert.org/vuls/id/521059http://www.osvdb.org/3326http://www.securityfocus.com/bid/4479https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-018
2002-04-22
Published