CVE-2000-0304

CVSS 2.0 Score 5.0 of 10 (medium)

Details

Published May 10, 2000
Updated: Nov 20, 2024

Summary

CVE-2000-0304 is a denial-of-service vulnerability affecting Microsoft IIS 4.0 and 5.0 servers with the IISADMPWD virtual directory installed. A remote attacker can cause a service disruption by sending a malformed request to the inetinfo.exe program. This vulnerability, also known as the "Undelimited .HTR Request" issue, allows an attacker to manipulate the parsing of .HTR files, leading to memory exhaustion and ultimately crashing the server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share