Main > Security & Privacy > Encrypting >

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098)

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098)

Sponsored Links

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 202.1KB
Platform: Windows 2000
License: Freeware
Price:
Downloads: 13
Date added: 2000-12-21
Publisher: Microsoft. Corp.

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) description

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) is launched as an important and helpful patch to remove a security vulnerability in a component that ships as part of Microsoft Windows 2000. The vulnerability could allow a malicious Web site operator to learn the names and properties of files and folders on the machine of a visiting user.

An ActiveX control that ships as part of Indexing Service is incorrectly marked as 'safe for scripting', thereby enabling it to be executed by Web site applications. The control at issue here could be used to enumerate files and folders and to view their properties. It would not be necessary for Indexing Service to be running in order for the vulnerability to be exploited; however, if it were running, the control also could be used to search for files containing specific words. The vulnerability could not be used to read files, except via a fairly unlikely scenario discussed in detail in the FAQ. It could not be used under any conditions to change, add, or delete information on the user's computer.

A patch has been provided for Indexing Service 3.0, but not for Index Server 2.0. This is primarily due to the different delivery vehicles for the two versions. Indexing Service 3.0 ships as part of all versions of Windows 2000; thus, the vulnerability could affect all Windows 2000 users. In contrast, Index Server 2.0 ships as part of the Windows NT 4.0 Option Pack; thus, to be affected by the vulnerability in Index Server 2.0, a Webmaster would need to browse untrustworthy Internet sites from a Web server, which is contrary to normal recommended practices.

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Screenshot

Advertisements

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Keywords

Bookmark Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098)

Hyperlink code:
Link for forum:

Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Copyright

WareSeeker periodically updates pricing and software information of Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Windows 2000 Indexing Service File Enumeration Vulnerability Patch (MS00-098) Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
This patch eliminates a security vulnerability in Microsoft Windows 2000. The vulnerability could allow enable a malicious user to potentially run code on another user's machine Free Download
Windows 2000 RDP Protocol Security Vulnerability Patch MS02-051 is a professional and smart patch which eliminates two vulnerabilities affecting the implementation of the RDP protocol. Free Download
Windows 2000 Telnet Server Flooding Vulnerability Patch is a simple and salutary vulnerability which has been discovered in the Telnet Server that ships with Microsoft Windows 2000. Free Download
Network Dynamic Data Exchange (DDE) is a technology that enables applications on different Windows computers to dynamically share data Free Download
Windows 2000 LPC Vulnerability Patch is a highly-efficient, high-quality patch which eliminates several security vulnerabilities that could allow a range of effects, from denial of service attacks to, in some cases, privilege elevation. Free Download
Prevent users from crashing your system by sending malformed data frames to your PC's infrared port. Free Download
Windows 2000 Malformed RPC Packet Vulnerability Patch is considered as an impressive and unique patch which eliminates a security vulnerability in Microsoft Windows 2000. Free Download
Windows 2000 Invalid RDP Data Memory Leak Vulnerability is considered as a professional and smart update which eliminates the 'Invalid RDP Data can Cause Terminal Service Failure' vulnerability in computers running Windows 2000, and is discussed in Microsoft Security Bulletin MS01-052. Free Download