Microsoft Index Server installed with IIS 4.0 could allow a local attacker to obtain physical path information

iis-indexserver-reveal-path (7559) The risk level is classified as LowLow Risk

Description:

Microsoft Index Server installed with Microsoft Internet Information Server (IIS) creates a registry subkey that contains the physical path of directories that are indexed. A local attacker could access the HKLM\System\CurrentControlset\Control\ContentIndex\Catalogs subkey in the AllowedPaths registry key to obtain directory path information. An attacker could use this vulnerability to launch further attacks against the affected host.

Platforms Affected:

  • Microsoft, Index Server 2.0

Remedy:

No remedy available as of November 29, 2008.

Consequences:

Obtain Information

References:

  • BugTraq Mailing List, Tue, 23 Mar 1999 23:40:55 -0000, Index Server 2.0 and the Registry at http://archives.neohapsis.com/archives/bugtraq/1999_1/1084.html.
  • BID-476: NT Index Server Remote Registry Vulnerability
  • CVE-1999-1397: Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.

Reported:

Mar 23, 1999

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page