Two Problems in ISA Server 2000

Microsoft Internet Security and Acceleration (ISA) Server 2000 Service Pack 2 (SP2) contains two vulnerabilities.

ITPro Today

June 14, 2005

1 Min Read
ITPro Today logo

TwoProblems in ISA Server 2000?

ReportedJune 14, 2005 by Microsoft

VERSIONS AFFECTED

Microsoft Internet Security andAcceleration (ISA) Server 2000 Service Pack 2 includingMicrosoft Small Business Server 2000

DESCRIPTION

Microsoft InternetSecurity and Acceleration (ISA) Server 2000 Service Pack 2 (SP2)contains two vulnerabilities. ISA Server doesn't properly processmalformed HTTP requests, which could allow an intruder to poison thecache, bypass content restrictions, access unauthorized content, orredirect other ISA Server users to various content.

Also, the process usedby ISA Server to validate NetBIOS contains a vulnerability that couldallow an intruder to gain access with elevated privileges and toconnect to services using the NetBIOS protocol.

VENDOR RESPONSE

Microsoft released asecurity bulletin, CumulativeSecurity Update for ISA Server 2000 (899753),and an associated patch to correct these problems.

CREDITS

Steve Orrin ofWatchfire reported the HTTP request processing vulnerability

HanValk reported the NetBIOS vulnerability


Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like