Vulnerability record · CVE-2002-0371 · published 3 July 2002
CVE-2002-0371: Microsoft IE and Proxy/ISA Server gopher client buffer overflow
Microsoft · Internet Explorer
The gopher client in Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, and ISA Server 2000 contains a buffer overflow triggered by a long response from a gopher server reached via a gopher:// URL. A remote attacker can redirect a victim to a malicious or simulated gopher server and overflow the buffer, potentially executing arbitrary code in the context of the affected process.
Description
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high EPSS score, but exploitation requires user interaction and the affected products are legacy.
What it is
The gopher client in Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, and ISA Server 2000 contains a buffer overflow triggered by a long response from a gopher server reached via a gopher:// URL. A remote attacker can redirect a victim to a malicious or simulated gopher server and overflow the buffer, potentially executing arbitrary code in the context of the affected process.
Impact
An attacker can execute arbitrary code on the victim's system or on the proxy/ISA server, depending on which component processes the gopher response. This can lead to full compromise of the affected host or proxy.
Attack surface
Reached remotely over the network via a crafted gopher:// URL that redirects the user to an attacker-controlled or simulated gopher server. No authentication is required, but the victim must be induced to follow the URL or otherwise have the gopher response processed by the affected client or proxy.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.54441, 98.962 percentile), indicating a high modeled likelihood of exploitation activity, though the record does not confirm public exploit code.
What to do
- Apply the Microsoft security bulletin MS02-027 update for Internet Explorer, Proxy Server 2.0, and ISA Server 2000.
- Disable or block the gopher protocol handler in Internet Explorer and restrict gopher:// URL handling at the proxy and gateway.
- Block outbound gopher traffic (TCP port 70) at network egress and proxy rules where not explicitly required.
- Upgrade or retire end-of-life products such as Proxy Server 2.0 and ISA Server 2000 that no longer receive security fixes.
Detection
- Monitor proxy, firewall, and IDS logs for gopher:// URLs and outbound connections to TCP port 70, especially to untrusted or newly seen hosts.
- Inspect HTTP and proxy logs for redirects to gopher:// schemes and for unusually long gopher server responses.
- Watch for process crashes or anomalous child processes spawned by Internet Explorer, Proxy Server, or ISA Server after gopher-related activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0371), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.