Denial of Service in Microsoft ISA Server 2000 and Microsoft Proxy Server 2.0

A vulnerability in Microsoft’s ISA Server 2000 and Proxy Server 2.0 can result in a Denial of Service (DoS) condition on the vulnerable server.

Ken Pfeil

April 13, 2003

2 Min Read
ITPro Today logo

Reported April 9, 2003, byMicrosoft.

 

 

VERSIONS AFFECTED

 

·        Microsoft ISA Server 2000

·        Microsoft Proxy Server 2.0

 

DESCRIPTION

 

Avulnerability in Microsoft’s ISA Server 2000 and Proxy Server 2.0 can resultin a Denial of Service (DoS) condition on the vulnerable server. Thisvulnerability is a result of flaw in the Winsock Proxy service. Thevulnerability lets malicious users on the internal network send speciallycrafted packets to cause the server to stop responding to internal and externalrequests. Receipt of such a packet causes CPU utilization on the server to reach100 percent.

 

VENDOR RESPONSE

 

Microsofthas released Security Bulletin MS03-012,"Flaw In Winsock Proxy Service And ISA Firewall Service Can Cause Denial OfService (331066)," to address this vulnerability and recommends thataffected users immediately apply the patch mentioned in the bulletin.

 

CREDIT          

Discovered by Microsoft.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like