This application requires Javascript for optimal performance.

MS.IIS.W3who.Dll.ISAPI.Remote.Buffer.Overflow

Release Date

Dec 24, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

It indicates a possible attempt to exploit a Buffer Overflow Vulnerability in Microsoft Windows 2000 Resource Kit W3Who.DLL

This may allow an attacker to execute arbitrary code on the vulnerable system via a long query string or possibly cause denial of service.

Affected Products

Microsoft Windows 2000 Resource Kit W3Who.DLL

Recommended Actions

Restrict access to the DLL.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2004-1134

Reference/s

http://www.securityfocus.com/bid/11820 (BugTraq)

Reference: VID-30430