Vulnerability record · CVE-2001-0241 · published 27 June 2001
CVE-2001-0241: Windows 2000 IIS Internet Printing ISAPI buffer overflow
Microsoft · Windows 2000
The Internet Printing ISAPI extension in Windows 2000 contains a buffer overflow reachable through IIS 5.0. A long print request passed to the extension can corrupt memory and let a remote attacker execute code in the context of the IIS service. The flaw matters because it is network-reachable, needs no authentication, and yields full control of the host.
Description
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable buffer overflow with a CVSS 2.0 score of 10, full host compromise, and very high EPSS despite the absence of KEV listing.
What it is
The Internet Printing ISAPI extension in Windows 2000 contains a buffer overflow reachable through IIS 5.0. A long print request passed to the extension can corrupt memory and let a remote attacker execute code in the context of the IIS service. The flaw matters because it is network-reachable, needs no authentication, and yields full control of the host.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the IIS process, described as root-level control of the server. That gives full read/write access to data and the ability to pivot further into the network.
Attack surface
Reached over the network through IIS 5.0 by sending a crafted print request to the Internet Printing ISAPI extension. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.857, 99.7th percentile) and a SecurityFocus reference carries an Exploit tag, indicating public exploit code exists. No ransomware association is documented.
What to do
- Apply Microsoft security bulletin MS01-023, which addresses this vulnerability.
- If the Internet Printing ISAPI extension is not needed, remove or disable it and block access to the associated virtual directory.
- Restrict or filter external access to IIS 5.0 print-related endpoints at the perimeter.
- Retire or isolate Windows 2000/IIS 5.0 systems that cannot be patched.
- Monitor vendor and CERT/CC advisory CA-2001-10 for additional guidance.
Detection
- Inspect IIS and web server logs for unusually long or malformed requests to the Internet Printing ISAPI extension or its virtual directory.
- Alert on IIS worker process crashes or restarts that coincide with print-related requests.
- Hunt for unexpected child processes or command execution spawned by the IIS service account.
- Review network traffic to print-related IIS endpoints for oversized payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0241 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.