← Vulnerability feed

Vulnerability record · CVE-2001-0546 · published 20 September 2001

CVE-2001-0546: Microsoft isa server vulnerability

Microsoft · Isa Server

Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.

5.0 CVSS 2.0 Medium EPSS 17% · top 3.0%
5.0CVSS 2.0 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-7027Microsoft isa server vulnerabilityMicrosoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remo…EPSS 15%9.3CVE-2009-0562Microsoft isa server vulnerabilityThe Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, …EPSS 26%9.3CVE-2009-1534Microsoft Office Web Components ActiveX control buffer overflowThe Office Web Components ActiveX control contains a buffer overflow that is triggered by crafted property values. Because the control is loaded in t…EPSS 52%analysed9.3CVE-2009-1136Microsoft Office Web Components ActiveX control remote code executionThe Microsoft Office Web Components Spreadsheet ActiveX control (OWC10/OWC11) can be abused through a crafted call to the msDataSourceObject method w…EPSS 62%analysed9.0CVE-2009-1135Microsoft isa server permissions and access controls vulnerabilityMicrosoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w…EPSS 26%7.5CVE-2006-3652Microsoft isa server vulnerabilityMicrosoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing…EPSS 19%7.5CVE-2006-1651Microsoft isa server vulnerabilityMicrosoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE:…EPSS 15%7.5CVE-2005-1215Microsoft isa server vulnerabilityMicrosoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet …EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2001-0546), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.