Vulnerability record · CVE-2000-0408 · published 11 May 2000
CVE-2000-0408: Microsoft IIS malformed URL extension data denial of service
Microsoft · Internet Information Server
IIS 4.05 and 5.0 mishandle URLs containing a long, complex sequence of apparent file extensions, allowing a remote attacker to crash or hang the service. The flaw is a denial of service in the URL parsing path and requires no authentication or user interaction. It matters because a single crafted request can take down a web server that is directly reachable from the network.
Description
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityAvailability-only denial of service with no code execution, but a high EPSS score and unauthenticated network reachability keep it relevant for exposed legacy IIS.
What it is
IIS 4.05 and 5.0 mishandle URLs containing a long, complex sequence of apparent file extensions, allowing a remote attacker to crash or hang the service. The flaw is a denial of service in the URL parsing path and requires no authentication or user interaction. It matters because a single crafted request can take down a web server that is directly reachable from the network.
Impact
An attacker can cause a denial of service, making the IIS web service unavailable to legitimate users. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reached over the network by sending a crafted HTTP request with a long, complex URL containing many apparent file extensions to the IIS server. No authentication or user interaction is required, per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at roughly 0.58 (99th percentile), indicating elevated predicted exploitation activity. Reference tags provide no exploit-specific information.
What to do
- Apply the Microsoft security bulletin MS00-030 update for IIS 4.05 and 5.0, or upgrade to a supported IIS release.
- Restrict direct internet exposure of legacy IIS servers behind a reverse proxy or WAF that normalizes and limits URL length and extension count.
- Enforce request-line and URL length limits at the web server or front-end proxy to reject malformed, overly complex URLs.
- Monitor IIS process health and configure automatic restart/recovery so a crash does not cause prolonged outage.
Detection
- Alert on HTTP request lines with unusually long URLs or an abnormally high count of dot-delimited extensions.
- Monitor IIS worker process crashes, restarts, or unexpected service terminations correlated with inbound requests.
- Baseline normal URL length and extension patterns per application and flag outliers at the proxy or WAF.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0408 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0408), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.