There is a flaw in the way nsiislog.dll processes incoming client
requests. A vulnerability exists because an attacker could send
specially formed HTTP request (communications) to the server that
could cause IIS to fail or execute code on the user's system.
Windows Media Services is not installed by default on Windows 2000.
An attacker attempting to exploit this vulnerability would have to
be aware which computers on the network had Windows Media Services
installed on it and send a specific request to that server.
|