PT-2002-1715 · Microsoft · Frontpage Server Extensions
Published
2002-10-10
·
Updated
2019-04-30
·
CVE-2002-0692
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft FrontPage Server Extensions (FPSE) versions 2000 and 2002
Description
The issue is related to a buffer overflow in the SmartHTML Interpreter (shtml.dll) of Microsoft FrontPage Server Extensions. This can be exploited by remote attackers through a specific type of web file request, potentially leading to a denial of service due to CPU consumption or allowing the execution of arbitrary code.
Recommendations
For Microsoft FrontPage Server Extensions 2000, update to a version that fixes this issue.
For Microsoft FrontPage Server Extensions 2002, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the SmartHTML Interpreter (shtml.dll) to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frontpage Server Extensions