MS.Content.Management.Server.Code.Execution

description-logoDescription

Microsoft Content Management Server (MCMS) does not properly handle certain characters in a crafted HTTP GET request. This may allow remote attackers to execute arbitrary code.

affected-products-logoAffected Products

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2.

Impact logoImpact

System compromise, remote code execution.

recomended-action-logoRecommended Actions

Microsoft has released an advisory along with fixes to address this issue in supported versions of affected applications.
Microsoft Content Management Server 2001 SP1
Microsoft Security Update for Microsoft Content Management Server 2001 (KB924430)
http://www.microsoft.com/downloads/details.aspx?familyid=0AAC923D-A6B8 -4023-9977-AEA6782DC1C7&displaylang=en
Microsoft Content Management Server 2002 SP2
Microsoft Security Update for Microsoft Content Management Server 2002 (KB924429)
http://www.microsoft.com/downloads/details.aspx?familyid=41D53931-BCF8 -43D9-9D16-592EBFB0AC04&displaylang=en

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)