Microsoft Internet Security and Acceleration (ISA) Server web proxy service is reported prone to a remote denial of service vulnerability. The issue is reported to exist because ISA server may fail to terminate a redirect URI string with a NULL byte when copying the URI into a temporary buffer. As a result of this failure, a read operation performed on the temporary buffer will read beyond its bounds, potentially resulting in a read access violation in the W3proxy.exe executable.
Microsoft Internet Security and Acceleration (ISA) Server web proxy service is reported prone to a remote denial of service vulnerability. The issue is reported to exist because ISA server may fail to terminate a redirect URI string with a NULL byte when copying the URI into a temporary buffer. As a result of this failure, a read operation performed on the temporary buffer will read beyond its bounds, potentially resulting in a read access violation in the W3proxy.exe executable.