Microsoft has just released a fix for the recently discovered security flaw in Microsoft Index Server 2.0 & Indexing Service in Windows 2000. Idq.dll contains an unchecked buffer in a section of code that handles input URLs. An attacker who could establish a web session with a server on which idq.dll is installed could conduct a buffer overrun attack and execute code on the web server. Idq.dll runs in the System context, so exploiting the vulnerability would give the attacker complete control of the server and allow him to take any desired action on it. Clearly, this is a serious vulnerability, and Microsoft urges all customers to take action immediately. Select your operating system below to download the patch.
Patches for Windows 2000 Datacenter Server are hardware-specific and available only from the original equipment manufacturer. The vulnerability will be eliminated in the next Windows XP beta update as well as the final, released version of the product.
|