Print... | Close

Security Update, March 13, 2001

This update resolves the "Malformed WebDAV Request Can Cause IIS to Exhaust CPU Resources" security vulnerability in Internet Information Services (IIS) 5.0, and is discussed in Microsoft Security Bulletin MS01-016. Download now to prevent a malicious user from temporarily disrupting your Web services.

This vulnerability exists because Web distributed authoring and versioning (WebDAV) incorrectly processes specially malformed requests. (WebDAV is a component of IIS 5.0 that enables users to add and manage content on a Web server remotely). If a malicious user sends a stream of specially malformed requests to an affected server, the Central Processing Unit (CPU) usage will significantly increase, disrupting Web services for as long as the stream of malformed requests continues.

For more information about this issue, read Microsoft Security Bulletin MS01-016. (This site is in English.)

System Requirements
This update applies to Windows 2000 computers running IIS 5.0.

How to use
Restart your computer to complete the installation.

How to uninstall
  1. Click Start, point to Settings, and then click Control Panel.
  2. Double-click Add/Remove Programs.
  3. Select Windows 2000 Hotfix (Pre SP2) [See Q291845 for more information], and then click Change/Remove to uninstall.

Print... | Close