Click Here to Install Silverlight*
United StatesChange|All Microsoft Sites
Microsoft
Download Center 
Search Advanced Search

ISA Server 2000 - Vulnerability in H.323 Filter Can Cause Remote Code Execution (816458)

Brief Description
A critical security vulnerability exists in the H.323 filter for Microsoft ISA Server 2000 that could allow an attacker to overflow a buffer on the Microsoft Firewall Service in Microsoft ISA Server 2000.

On This Page

Quick Details
File Name:ISA2000-KB816458-x86.exe
Version:3.0
Date Published:1/13/2004
Language:English
Download Size:242 KB
Estimated Download Time: 1 min 56K

Change Language:
  

Overview

A critical security vulnerability exists in the H.323 filter for Microsoft ISA Server 2000 that could allow an attacker to overflow a buffer on the Microsoft Firewall Service in Microsoft ISA Server 2000. The vulnerability results because the H.323 filter for the Microsoft Firewall Service does not perform proper boundary checks on specially formatted H.323 packets. An attacker who successfully exploited this vulnerably could attempt to run code of their choosing in the security context of the Microsoft Firewall Service, giving the attacker complete control over the system. ISA Servers running in cache mode are not vulnerable because the Microsoft Firewall Service is disabled by default. However, since the H.323 filter is enabled by default on systems installed in Integrated or Firewall mode, installing this security update is highly recommended.

 Top of page

System Requirements

  • Supported Operating Systems: Windows 2000; Windows Server 2003
• Microsoft Internet Security and Acceleration Server 2000 Service Pack 1

 Top of page

Instructions

  1. Click the Download link on this page to start the download, or choose a different language from the drop-down list and click Go.
  2. Do one of the following:
    • To start the installation immediately, click Open or Run this program from its current location.
    • To copy the download to your computer for installation at a later time, click Save or Save this program to disk.

 Top of page

Additional Information

Complete information can be found by following the links in the “Related Resources” section above.

 Top of page

 Top of page


© 2009 Microsoft Corporation. All rights reserved. Contact Us |Terms of Use |Trademarks |Privacy Statement