Vulnerability record · CVE-2004-1134 · published 10 January 2005
CVE-2004-1134: Microsoft W3Who ISAPI buffer overflow via long query string
Microsoft · W3who.Dll
The Microsoft W3Who ISAPI extension (w3who.dll) contains a buffer overflow that can be triggered by a long query string. A remote, unauthenticated attacker can crash the service and possibly execute arbitrary code in the web server process. The record does not specify affected Windows or IIS versions.
Description
Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus a very high EPSS score.
What it is
The Microsoft W3Who ISAPI extension (w3who.dll) contains a buffer overflow that can be triggered by a long query string. A remote, unauthenticated attacker can crash the service and possibly execute arbitrary code in the web server process. The record does not specify affected Windows or IIS versions.
Impact
An attacker can cause a denial of service against the IIS server and potentially execute arbitrary code with the privileges of the ISAPI process.
Attack surface
Reachable remotely over the network through HTTP requests to the W3Who ISAPI endpoint; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high (0.72326, 99.4th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Microsoft security update addressing the W3Who ISAPI buffer overflow, or remove/disable w3who.dll if it is not required.
- Remove the W3Who ISAPI extension mapping from IIS if the component is unused.
- Restrict network access to IIS servers and filter unusually long or malformed query strings at the perimeter.
- Run IIS worker processes with least privilege to limit the impact of any code execution.
Detection
- Monitor IIS and Windows logs for crashes or restarts of w3who.dll or the worker process.
- Inspect web server access logs for abnormally long query strings targeting the W3Who ISAPI endpoint.
- Alert on unexpected child processes or command execution spawned by the IIS worker process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1134 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1134), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.