Print... | Close

Security Update, May 10, 2001

This update addresses the "Malformed Hit-Highlighting" security vulnerability in Windows NT® 4.0 computers running Index Server 2.0, and is discussed in Microsoft Security Bulletin MS01-025. Download now to help prevent a malicious user from reading files on your Web server.

When you conduct a search using Indexing Server 2.0, the hit-highlighting function provides search results that highlight portions of documents that satisfy your search query. This vulnerability exists because Indexing Server 2.0 doesn't set the correct parameters for hit-highlighting search requests. If a malicious user provides a specific type of malformed request, it retrieves files on the server, regardless of the permissions that have been set by the administrator.

By design, the hit-highlighting feature allows the user to specify the name of the document to be hit-highlighted. The user should only be able to request documents within the server's virtual directories; however, if a specific type of malformed argument is provided, it can be used to request a file by its physical location on the drive.

For more information about this vulnerability, read Microsoft Security Bulletin MS01-025. (This site is in English.)

System Requirements
This update applies to Windows NT 4.0 computers running Index Server 2.0.

How to use
Restart your computer to complete the installation.

How to uninstall
Uninstall is not available.

Print... | Close