Reported December 19 by Microsoft

VERSIONS AFFECTED
  • Microsoft Index Server 2.0
  • Indexing Service 3.0

DESCRIPTION

An ActiveX component that ships as part of Indexing services has been incorrectly marked as safe for scripting enabling it to be executed by Web-site applications.  A malicious Web-site operator can use this component to enumerate files and folders on the client machines.

VENDOR RESPONSE

Microsoft has issued a security bulletin, MS00-098, and a patch that protects Indexing Service 3.0 is available at the following: 

http://www.microsoft.com/Downloads/Release.asp?releaseID=26595

Microsoft did not release a patch for Index Server 2.0, however, as Index Server 2.0 is part of Windows NT Option Pack and should be installed only on  Web servers that are not used to surf the Web.

CREDIT
Discovered b
y Microsoft