Microsoft IE 5.x, Outlook, Outlook Express, and Windows 2000 with Index Server Vulnerable to Remote File Searching
An issue with an ActiveX control allows users to search for any file on a vulnerable system
November 9, 2000
Reported November 10, 2000 by Georgi Guninski VERSIONS AFFECTED DESCRIPTIONAn issue with the "ixsso.query" ActiveX object causes Internet Explorer 5.x, Outlook, Outlook Express, and Windows 2000 with Microsoft Index Server to be vulnerable to unauthorized file searching. DEMONSTRATION Georgi Guninski made the following code available; --------indexserv1.html------------------------------------------- --------------------------------------------------------------------- VENDOR RESPONSE Georgi Guninski reported this issue to Microsoft on November 6, 2000. I contacted Microsoft as well and they are working on a patch. Unfortunately, Microsoft was only given four days to address the issue and has not completed the patch. CREDITDiscovered by Georgi Guninski |
Read more about:
MicrosoftAbout the Author
You May Also Like