Vulnerability record · CVE-2002-0072 · published 22 April 2002
CVE-2002-0072: IIS w3svc.dll ISAPI filter null pointer crash on long URL
Microsoft · Internet Information Server
The w3svc.dll ISAPI filter used by Front Page Server Extensions and ASP.NET on IIS 4.0, 5.0 and 5.1 mishandles the error condition triggered by a long URL, causing the URL parser to dereference a null pointer. A remote, unauthenticated request can crash the affected IIS process, disrupting web service availability. The record is old and thin on affected-version detail beyond the IIS versions named in the description.
Description
The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated denial of service with high EPSS but only partial availability impact and no confirmed in-the-wild exploitation or KEV listing.
What it is
The w3svc.dll ISAPI filter used by Front Page Server Extensions and ASP.NET on IIS 4.0, 5.0 and 5.1 mishandles the error condition triggered by a long URL, causing the URL parser to dereference a null pointer. A remote, unauthenticated request can crash the affected IIS process, disrupting web service availability. The record is old and thin on affected-version detail beyond the IIS versions named in the description.
Impact
An attacker can cause a denial of service by crashing the IIS worker process, taking hosted sites offline until the service recovers. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP by sending a crafted long URL to an IIS server running the vulnerable w3svc.dll ISAPI filter; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.57 (99th percentile), indicating elevated predicted exploitation activity; reference tags are informational only and do not confirm public exploit code.
What to do
- Apply the Microsoft security bulletin MS02-018 update for IIS 4.0, 5.0 and 5.1, or upgrade to a supported IIS release.
- Disable Front Page Server Extensions and ASP.NET ISAPI filter mappings where they are not required.
- Enforce URL length limits and request filtering at the reverse proxy or WAF in front of IIS.
- Run IIS worker processes under a least-privilege account and enable automatic process recycling to limit outage duration.
Detection
- Alert on IIS worker process crashes or unexpected w3svc.dll faults in Windows event logs and crash dumps.
- Monitor web logs for abnormally long request URIs or repeated requests to FPSE/ASP.NET ISAPI endpoints.
- Track service availability gaps and rapid process restarts on IIS hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0072 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0072), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.