Vulnerability record · CVE-2000-0246 · published 30 March 2000
CVE-2000-0246: IIS ISAPI processing on UNC-mapped virtual directories exposes source code
Microsoft · Commercial Internet System
IIS 4.0 and 5.0 fails to properly perform ISAPI extension processing when a virtual directory is mapped to a UNC share. This causes ASP and other source files to be served or read instead of executed, exposing application source code. The flaw matters because source disclosure can reveal credentials, business logic and further attack paths.
Description
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityRemote unauthenticated source code disclosure with very high EPSS, though limited to environments using UNC-mapped virtual directories.
What it is
IIS 4.0 and 5.0 fails to properly perform ISAPI extension processing when a virtual directory is mapped to a UNC share. This causes ASP and other source files to be served or read instead of executed, exposing application source code. The flaw matters because source disclosure can reveal credentials, business logic and further attack paths.
Impact
A remote attacker can read the source code of ASP and other files hosted on the affected virtual directory. This gives the attacker sensitive application internals rather than direct code execution.
Attack surface
Reachable over the network via HTTP requests to the affected IIS virtual directory; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector. It only applies where a virtual directory is mapped to a UNC share.
Exploitation
Not listed in CISA KEV and no exploit tags are present in the references, but EPSS is very high (0.79976, 99.592nd percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Microsoft security bulletin MS00-019 update for IIS 4.0/5.0.
- Avoid mapping IIS virtual directories to UNC shares; host content on local volumes where possible.
- If UNC-mapped virtual directories are required, restrict share permissions and network access to the IIS server.
- Upgrade to a supported IIS version, as IIS 4.0/5.0 are long out of support.
Detection
- Review IIS metabase and configuration for virtual directories whose path is a UNC share (\\server\share).
- Monitor web server logs for requests returning ASP or source file content instead of executed output.
- Alert on HTTP responses containing ASP source markers such as '<%' or server-side script code.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0246 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0246), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.