Microsoft has released a patch that fixes a vulnerability in Index Server 2.0 which has an unchecked buffer in a function that processes search requests. If an overly long value were provided for a particular search parameter, it would overrun the buffer.
If the buffer were overrun with random data, it would cause Index Service to fail. If it were overrun with carefully selected data, code of the attacker's choice could be made to run on the server, in the Local System security context.
Requirements:
Windows NT
Comments not found