Two Problems in ISA Server 2000
Microsoft Internet Security and Acceleration (ISA) Server 2000 Service Pack 2 (SP2) contains two vulnerabilities.
June 14, 2005
TwoProblems in ISA Server 2000?
ReportedJune 14, 2005 by Microsoft
VERSIONS AFFECTED
Microsoft Internet Security andAcceleration (ISA) Server 2000 Service Pack 2 includingMicrosoft Small Business Server 2000 |
DESCRIPTION
Microsoft InternetSecurity and Acceleration (ISA) Server 2000 Service Pack 2 (SP2)contains two vulnerabilities. ISA Server doesn't properly processmalformed HTTP requests, which could allow an intruder to poison thecache, bypass content restrictions, access unauthorized content, orredirect other ISA Server users to various content.
Also, the process usedby ISA Server to validate NetBIOS contains a vulnerability that couldallow an intruder to gain access with elevated privileges and toconnect to services using the NetBIOS protocol.
VENDOR RESPONSE
Microsoft released asecurity bulletin, CumulativeSecurity Update for ISA Server 2000 (899753),and an associated patch to correct these problems.
CREDITS
Steve Orrin ofWatchfire reported the HTTP request processing vulnerability
HanValk reported the NetBIOS vulnerability
About the Author
You May Also Like