Vulnerability record · CVE-2000-0457 · published 11 May 2000
CVE-2000-0457: IIS ISM.DLL .HTR request allows remote file fragment reading
Microsoft · Internet Information Server
ISM.DLL in Microsoft IIS 4.0 and 5.0 mishandles requests that append a large number of encoded spaces (%20) and end with a .htr extension, letting a remote attacker read file contents. Because the flaw exposes file data without credentials, it can leak source code, configuration or other sensitive content from the web server.
Description
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows unauthenticated remote file disclosure and has a high EPSS score, though it affects only legacy IIS versions.
What it is
ISM.DLL in Microsoft IIS 4.0 and 5.0 mishandles requests that append a large number of encoded spaces (%20) and end with a .htr extension, letting a remote attacker read file contents. Because the flaw exposes file data without credentials, it can leak source code, configuration or other sensitive content from the web server.
Impact
An unauthenticated attacker gains read access to file contents on the affected IIS server, potentially exposing scripts, configuration and other sensitive files.
Attack surface
Reachable over the network through HTTP requests to IIS; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high at 0.52751 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply Microsoft security bulletin MS00-031 or the corresponding IIS patch, and remove or disable the .htr ISAPI handler if it is not required.
- Upgrade from IIS 4.0/5.0 to a supported IIS release.
- Restrict network exposure of IIS and block requests containing long runs of encoded spaces ending in .htr at the web application firewall or reverse proxy.
- Audit web-accessible directories for sensitive files that could be read if the handler remains enabled.
Detection
- Search IIS and proxy logs for requests containing long sequences of %20 followed by a .htr extension.
- Alert on .htr requests to ISM.DLL or the .htr ISAPI extension from unexpected clients.
- Monitor for anomalous HTTP requests with unusually high encoded-space counts or malformed path segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0457 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0457), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.