← Vulnerability feed

Vulnerability record · CVE-2000-0246 · published 30 March 2000

CVE-2000-0246: IIS ISAPI processing on UNC-mapped virtual directories exposes source code

Microsoft · Commercial Internet System

IIS 4.0 and 5.0 fails to properly perform ISAPI extension processing when a virtual directory is mapped to a UNC share. This causes ASP and other source files to be served or read instead of executed, exposing application source code. The flaw matters because source disclosure can reveal credentials, business logic and further attack paths.

5.0 CVSS 2.0 Medium EPSS 80% · top 0.4%
5.0CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote unauthenticated source code disclosure with very high EPSS, though limited to environments using UNC-mapped virtual directories.

What it is

IIS 4.0 and 5.0 fails to properly perform ISAPI extension processing when a virtual directory is mapped to a UNC share. This causes ASP and other source files to be served or read instead of executed, exposing application source code. The flaw matters because source disclosure can reveal credentials, business logic and further attack paths.

Impact

A remote attacker can read the source code of ASP and other files hosted on the affected virtual directory. This gives the attacker sensitive application internals rather than direct code execution.

Attack surface

Reachable over the network via HTTP requests to the affected IIS virtual directory; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector. It only applies where a virtual directory is mapped to a UNC share.

Exploitation

Not listed in CISA KEV and no exploit tags are present in the references, but EPSS is very high (0.79976, 99.592nd percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the Microsoft security bulletin MS00-019 update for IIS 4.0/5.0.
  • Avoid mapping IIS virtual directories to UNC shares; host content on local volumes where possible.
  • If UNC-mapped virtual directories are required, restrict share permissions and network access to the IIS server.
  • Upgrade to a supported IIS version, as IIS 4.0/5.0 are long out of support.

Detection

  • Review IIS metabase and configuration for virtual directories whose path is a UNC share (\\server\share).
  • Monitor web server logs for requests returning ASP or source file content instead of executed output.
  • Alert on HTTP responses containing ASP source markers such as '<%' or server-side script code.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0246 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7269IIS 6.0 WebDAV ScStoragePathFromUrl buffer overflow enables remote code executionA buffer overflow in the ScStoragePathFromUrl function of the WebDAV service in IIS 6.0 on Windows Server 2003 R2 allows remote code execution via a …KEVEPSS 100%analysed10.0CVE-2010-3972Microsoft IIS FTP Service heap buffer overflow via crafted FTP commandA heap-based buffer overflow exists in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 as shipped w…EPSS 95%analysed10.0CVE-2008-4301Microsoft internet information services vulnerabilityA certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argum…EPSS 17%10.0CVE-2008-0075Microsoft IIS ASP code injection allows remote code executionCVE-2008-0075 is an unspecified code injection flaw in Microsoft Internet Information Services (IIS) 5.1 through 6.0 that is triggered by crafted inp…EPSS 57%analysed10.0CVE-2007-2815IIS 5.0 webhits.dll hit-highlighting authentication bypassThe hit-highlighting feature in webhits.dll on Microsoft IIS 5.0 relies only on Windows NT ACLs, so it fails to enforce NTLM or basic authentication.…EPSS 73%analysed10.0CVE-2003-0819Microsoft proxy server memory buffer overflow vulnerabilityBuffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in …EPSS 41%10.0CVE-2003-0224Microsoft internet information services vulnerabilityBuffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a…EPSS 18%10.0CVE-2001-0500Microsoft IIS Index Server ISAPI idq.dll buffer overflowA buffer overflow in the ISAPI extension idq.dll, used by Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier, is triggered by a l…EPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2000-0246), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.