Print... | Close

Security Update, July 17, 2000

This update resolves two security vulnerabilities in Internet Information Server (IIS) 4.0, the "Absent Directory Browser Argument" vulnerability and the "File Fragment Reading via .HTR" vulnerability, and is discussed in Microsoft Security Bulletin MS00-044. Download now to help prevent a malicious user from exploiting these vulnerabilities to slow the performance of an affected Web server or, under very specific conditions, obtain the source code of certain types of files on a Web server.

The .htr files are scripts that can be used in Windows NT® 4.0 to change passwords, and thatadministrators can use to perform a variety of password administration functions. Neither of these vulnerabilities allow data to be changed, added, or deleted on the server, nor does either allow administrative control over the affected computer.

Details about the two vulnerabilities that are addressed in this update:

For more information about these vulnerabilities, read Microsoft Security Bulletin MS00-044. (This site is in English.)

System Requirements
This update applies to Windows NT 4.0 computers running IIS 4.0.

How to use
Restart your computer to complete the installation.

How to uninstall
  1. Click Start, point to Settings, and then click Control Panel.
  2. Double-click Add/Remove Programs.
  3. Select Windows NT Hotfix [See Q267560 for more information], and then click Change/Remove to uninstall.

Print... | Close