peter bassill · operator
$ cve CVE-2001-0500 JSON

CVE-2001-0500 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 96.7% (pctl 100)

Patch early

A public exploit exists.

Description

Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS96.67% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2001-07-21
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftindex server
microsoftindexing service
microsoftinternet information server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD