Advertisement
Promo

Industry watch Toolkit

FrontPage flaw puts servers in jeopardy

Published: 26 Sep 2002 07:43 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft warned Web site administrators on Wednesday that a flaw in its FrontPage extensions could allow an attacker to take control of their servers or cause the computers to seize up.

In its 53rd advisory for the year, the software giant said a vulnerability in the SmartHTML interpreter could be exploited to cause a denial-of-service attack on the Web server if the computer had FrontPage Server Extensions 2000 running. For FrontPage Server Extensions 2002, the flaw could result in the attacker running the code of their choice, essentially taking control of the server.

"If a request for a certain type of Web file is made in a particular way... (it could cause) the SmartHTML interpreter to cycle endlessly, consuming all the server's CPU availability," according to Microsoft's advisory.

The company urged administrators to apply the patch for the problem or run the Internet Information Server lockdown tool, a security application that disables many of the potentially dangerous functions in Microsoft's IIS Web server.

Despite launching its Trustworthy Computing initiative in January, the software giant has racked up more than 70 vulnerabilities outlined in 53 advisories this year. Last week, Microsoft revealed three flaws in its Java virtual machine software.

The same day, the US government unveiled the National Strategy for Securing Cyberspace. While the strategy urged companies and security researchers to solve vulnerability issues quickly and discretely, it didn't highlight software companies' problems in eliminating such problems.

Microsoft credited Digital Defense Services for finding the problem.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
48 out of 100 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Discussions

Tezzer Tezzer

The only surprise...

Wednesday 16 December 2009, 1:47 PM

3 comments
ator1940 ator1940

Cloud apps

Wednesday 16 December 2009, 1:33 PM

1 comment
ator1940 ator1940

MS copy?

Wednesday 16 December 2009, 1:25 PM

3 comments
J.A. Watson J.A. Watson

Big Surprise... NOT!

Wednesday 16 December 2009, 12:05 PM

3 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters