Microsoft IE 5.x, Outlook, Outlook Express, and Windows 2000 with Index Server Vulnerable to Remote File Searching

An issue with an ActiveX control allows users to search for any file on a vulnerable system

Steve Manzuik

November 9, 2000

1 Min Read
ITPro Today logo

Reported November 10, 2000 by Georgi Guninski

VERSIONS AFFECTED

DESCRIPTIONAn issue with the "ixsso.query" ActiveX object causes Internet Explorer 5.x, Outlook, Outlook Express, and Windows 2000 with Microsoft Index Server to be vulnerable to unauthorized file searching.

DEMONSTRATION

Georgi Guninski made the following code available;

--------indexserv1.html-------------------------------------------

---------------------------------------------------------------------

VENDOR RESPONSE

Georgi Guninski reported this issue to Microsoft on November 6, 2000.  I contacted Microsoft as well and they are working on a patch.  Unfortunately, Microsoft was only given four days to address the issue and has not completed the patch.

CREDITDiscovered by Georgi Guninski

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like