Skip navigation

Index Server Allows for Remote File Enumeration

Reported December 19 by Microsoft

  • Microsoft Index Server 2.0
  • Indexing Service 3.0


An ActiveX component that ships as part of Indexing services has been incorrectly marked as safe for scripting enabling it to be executed by Web-site applications.  A malicious Web-site operator can use this component to enumerate files and folders on the client machines.


Microsoft has issued a security bulletin, MS00-098, and a patch that protects Indexing Service 3.0 is available at the following:

Microsoft did not release a patch for Index Server 2.0, however, as Index Server 2.0 is part of Windows NT Option Pack and should be installed only on  Web servers that are not used to surf the Web.

Discovered b
y Microsoft

Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.