Reported December 19 by Microsoft
- Microsoft Index Server 2.0
- Indexing Service 3.0
An ActiveX component that ships as part of Indexing services has been incorrectly marked as safe for scripting enabling it to be executed by Web-site applications. A malicious Web-site operator can use this component to enumerate files and folders on the client machines.
Microsoft has issued a security bulletin, MS00-098, and a patch that protects Indexing Service 3.0 is available at the following:
Microsoft did not release a patch for Index Server 2.0, however, as Index Server 2.0 is part of Windows NT Option Pack and should be installed only on Web servers that are not used to surf the Web.
Discovered by Microsoft