Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098)
Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Ranking & Summary
Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) description
Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) is launched as an important and helpful patch to remove a security vulnerability in a component that ships as part of Microsoft Windows 2000. The vulnerability could allow a malicious Web site operator to learn the names and properties of files and folders on the machine of a visiting user.
An ActiveX control that ships as part of Indexing Service is incorrectly marked as 'safe for scripting', thereby enabling it to be executed by Web site applications. The control at issue here could be used to enumerate files and folders and to view their properties. It would not be necessary for Indexing Service to be running in order for the vulnerability to be exploited; however, if it were running, the control also could be used to search for files containing specific words. The vulnerability could not be used to read files, except via a fairly unlikely scenario discussed in detail in the FAQ. It could not be used under any conditions to change, add, or delete information on the user's computer.
A patch has been provided for Indexing Service 3.0, but not for Index Server 2.0. This is primarily due to the different delivery vehicles for the two versions. Indexing Service 3.0 ships as part of all versions of Windows 2000; thus, the vulnerability could affect all Windows 2000 users. In contrast, Index Server 2.0 ships as part of the Windows NT 4.0 Option Pack; thus, to be affected by the vulnerability in Index Server 2.0, a Webmaster would need to browse untrustworthy Internet sites from a Web server, which is contrary to normal recommended practices.
Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Screenshot
Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Keywords
Bookmark Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098)
Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- Microsoft PowerPoint 2000 SR-1 Update: Extended Pa
- Microsoft Outlook 2000 SR-1 Update: Java Permissio
- Microsoft Internet Information Server 5.0 Patch: H
- Microsoft Windows 2000 Patch: Malformed Environmen
- Microsoft Windows 2000 Patch: No Mapping of Virtua
- Microsoft Windows 2000 Patch: Protected Store Key
- Microsoft Windows 2000 Patch: Video Locks Up When
- Microsoft Exchange 2000 Server Standalone SMTP Sec Update
- Microsoft Word 2000 RTF Macro Vulnerability Patch
- Microsoft Word 2000 Update: Word Mail Merge Vulnerability 10-3-00
- Office 2000 HTML Object Tag Vulnerability Patch
- IE5.5 SP1 File Upload via Form Vulnerability Patch MS00-093
- SumInfos 1
- Microsoft Office 2000 SR-1 Update: Web Client Security MS01-001
- JPEG IFilter 1.0
- AimAtFile Fast File Search 4.0
- Microsoft Windows 2000 Patch: Indexing Service Fil
- Indexing Service Companion 3.1
- Windows 2000 HyperTerminal Buffer Overflow Vulnerability Patch May 25, 2001
- Microsoft Office 2000 SR-1 Update: Web Client Secu Update
- Microsoft Windows NT 4.0 Patch: RDISK Registry Enumeration File Update
- Microsoft Office 2000 Security Update: UA Control Vulnerability Update
- Microsoft Excel 2000 HTML Script Vulnerability Patch
- Microsoft Office 2000 Security Update: HTML Data