Intrusion Prevention

MS.Content.Management.Server.Code.Execution

Description

Microsoft Content Management Server (MCMS) does not properly handle certain characters in a crafted HTTP GET request. This may allow remote attackers to execute arbitrary code.

Affected Products

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2.

Impact

System compromise, remote code execution.

Recommended Actions

Microsoft has released an advisory along with fixes to address this issue in supported versions of affected applications.
Microsoft Content Management Server 2001 SP1
Microsoft Security Update for Microsoft Content Management Server 2001 (KB924430)
http://www.microsoft.com/downloads/details.aspx?familyid=0AAC923D-A6B8 -4023-9977-AEA6782DC1C7&displaylang=en
Microsoft Content Management Server 2002 SP2
Microsoft Security Update for Microsoft Content Management Server 2002 (KB924429)
http://www.microsoft.com/downloads/details.aspx?familyid=41D53931-BCF8 -43D9-9D16-592EBFB0AC04&displaylang=en

CVE References

CVE-2007-0938