Microsoft Security Bulletin MS00-084
Patch Available for 'Indexing Services Cross Site Scripting'
Originally posted: November 02, 2000
Updated: June 23, 2003
Microsoft has released a patch that eliminates a security vulnerability in Microsoft® Indexing Services for Windows 2000. This vulnerability could allow a malicious web site operator to misuse another web site as a means of attacking users.
Subsequent to the release of this bulletin, it was discovered that an available package for the version of the Indexing Service which shipped with the NT 4.0 Option Pack had never been released. The bulletin is being updated to include the download locations for that version of the fix.
- Microsoft Indexing Services for Windows 2000
- Microsoft Indexing Services for Windows NT 4.0
Note: The Indexing Service ships and installs with Windows 2000, but is not enabled by default. Users who are running web servers on Windows 2000 who have enabled Indexing Services are urged to apply this patch.
The Indexing Service for Windows NT 4.0 ships with the NT Option Pack, and is not installed or enabled by default.
Vulnerability Identifier: CVE-2000-0942
Support: This is a fully supported patch. Information on contacting Microsoft Product Support Services is available at http://support.microsoft.com/contactussupport/?ws=support.
Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.
The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.
- V1.0 (November 02, 2000): Bulletin Created.
- V1.1 (February 28, 2003): Updated links in Frequently Asked Questions section.
- V2.0 (April 9, 2003): Bulletin updated to reflect an available fix for the version of the Indexing Service which shipped with the NT 4.0 Option Pack. It is not installed or enabled by default.
- V2.1 (June 23, 2003): Updated links in Additional Information section.