Used IIS5 File-Fragment Reading via Malformed HTR Request Vulnerability Patch for Windows?


Editors’ Review

Download.com staff
This patch addresses a new variant of the 'File Fragment Reading via .HTR' vulnerability. It prevents attackers from gaining unauthorized access to server-side files.
  • Pros

    • Eliminates specific file fragment reading vulnerability
    • Secures web servers against malicious users
    • Addresses a critical security flaw
    • Provides a solution for businesses needing HTR functionality
  • Cons

    • Requires disabling HTR functionality if not patched
    • Affects users relying on HTR functionality
    • This is a security bulletin, not a full application

Used IIS5 File-Fragment Reading via Malformed HTR Request Vulnerability Patch for Windows?


Explore More


Full Specifications

GENERAL
Release
Latest update
Version
ms01-004
OPERATING SYSTEMS
Platform
Windows
Operating System
  • Windows 10
  • Windows 2000
Additional Requirements
Windows 2000
POPULARITY
Total Downloads
13,914
Downloads Last Week
0

Report Software

Program available in other languages


Last Updated


User Reviews

5/5

1 User Votes


Developer’s Description

Stop malicious users from controlling your Web server.
This vulnerability involves a new variant of the 'File Fragment Reading via .HTR' vulnerability, previous variants of which were discussed in Microsoft Security Bulletins MS00-031 and MS00-044. Like the original variants, this one could enable an attacker to request a file in a way that would cause it to be processed by the HTR ISAPI extension. The result of doing this is that fragments of server-side files, such as ASP files, could potentially be sent to the attacker.

Customers who have previously disabled the HTR functionality would not be affected by this vulnerability. Microsoft recommends that all customers who haven't already disabled HTR do so, unless there is a business-critical reason for keeping it. For the latter group of customers, this patch will eliminate this vulnerability.


Download.com
Your review for IIS5 File-Fragment Reading via Malformed HTR Request Vulnerability Patch