Print... | Close

Security Update, May 26, 2000

This update, also known as the "'Malformed Extension Data in URL' Vulnerability Update", eliminates a security vulnerability in Microsoft Internet Information Server. The vulnerability could be used to slow the performance of an affected server, or temporarily stop it altogether.

This is a denial of service vulnerability. If a malicious user requested a file from a Web server via an URL containing specially-malformed file extension data, the server could become unresponsive for some period of time.

This vulnerability won't cause a server to fail, cause any data to be lost, or take administrative control of the machine. The vulnerability simply provides a way for a malicious attacker to consume most or all CPU availability. Given enough time, the server would resume normal operation on its own.

For additional information on this issue, read Microsoft Security Bulletin MS00-030 or Microsoft Knowledge Base (KB) article Q260205. (These sites are in English.)

System Requirements

How to use
Restart your computer to complete the installation.

How to uninstall
Uninstall is not available.

Print... | Close