Article ID: 297860 - Last Review: November 21, 2006 - Revision: 6.4 MS01-044: IIS 5.0 Security and Post-Windows NT 4.0 SP5 IIS 4.0 Patch RollupThis article was previously published under Q297860 On This PageSUMMARY
Microsoft has released a rollup package for Internet Information Services (IIS) 5.0 and Internet Information Server (IIS) 4.0 that includes the functionality from all security patches released to date for IIS 5.0, and all patches released for IIS 4.0 since Windows NT 4.0 Service Pack 5. This article provides a timeline and the fixes included with each release. MORE INFORMATIONNOTE: These patches do not include fixes for vulnerabilities involving non-IIS products, such as the Front Page Server Extensions and Index Server, even though these products are closely associated with IIS and typically installed on IIS servers. There is, however, one exception for the August 15, 2001 release. The fix for the vulnerability affecting Index Server which is discussed in Microsoft Security Bulletin MS01-033
(http://www.microsoft.com/technet/security/bulletin/MS01-033.mspx)
is included in this patch because of the seriousness of the issue for IIS servers. At the time this article was written, the Microsoft Security Bulletins that discuss these vulnerabilities are as follows:
Microsoft Security Bulletin MS01-043
(http://www.microsoft.com/technet/security/bulletin/MS01-043.mspx)
NOTE: The fixes for the following vulnerabilities that affect IIS 4.0 are not included in the patch because they require administrative action instead of a software change. Administrators should ensure that in addition to applying this patch, they also take the administrative action discussed in the following bulletins:
Microsoft Security Bulletin MS01-025 (http://www.microsoft.com/technet/security/bulletin/ms01-025.mspx) Microsoft Security Bulletin MS00-084 (http://www.microsoft.com/technet/security/bulletin/ms00-084.mspx) Microsoft Security Bulletin MS00-006 (http://www.microsoft.com/technet/security/bulletin/ms00-006.mspx) Microsoft Security Bulletin MS00-028
(http://www.microsoft.com/technet/security/bulletin/ms00-028.mspx)
Microsoft Security Bulletin MS00-025 (http://www.microsoft.com/technet/security/bulletin/ms00-025.mspx) Microsoft Security Bulletin MS99-025 (http://www.microsoft.com/technet/security/bulletin/ms99-025.mspx) (which discusses the same issue as Microsoft Security Bulletin MS98-004) (http://www.microsoft.com/technet/security/bulletin/ms98-004.mspx) Microsoft Security Bulletin MS99-013 (http://www.microsoft.com/technet/security/bulletin/ms99-013.mspx) January 30, 2002Internet Information Services 5.0To resolve this problem, either obtain the hotfix referenced in this section or Windows 2000 Security Rollup Package 1 (SRP1). For additional information about SRP1, click the article number below to view the article in the Microsoft Knowledge Base:311401
(http://support.microsoft.com/kb/311401/EN-US/
)
Windows 2000 Security Rollup Package 1 (SRP1), January 2002
August 15, 2001For more information on this release, see the following Microsoft Security Bulletin:http://www.microsoft.com/technet/security/bulletin/ms01-044.mspx
(http://www.microsoft.com/technet/security/bulletin/ms01-044.mspx)
NOTE: These patches supersede those provided in the following security bulletins:
Microsoft Security Bulletin MS01-033
(http://www.microsoft.com/technet/security/bulletin/MS01-033.mspx)
Microsoft Security Bulletin MS01-026 (http://www.microsoft.com/technet/security/bulletin/ms01-026.mspx) (May 14, 2001 release of the IIS security rollup package) Internet Information Services 5.0The following file is available for download from the Microsoft Download Center:Collapse this image ![]() Release Date: August 15, 2001 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
In addition to the "superceded patches" listed above, this cumulative package contains the fixes discussed in the following Microsoft Knowledge Base articles:
294774
(http://support.microsoft.com/kb/294774/EN-US/
)
IIS loads ISAPI Extension In-process Even When Application is Marked for High Isolation
298340
(http://support.microsoft.com/kb/298340/EN-US/
)
Patch Available for WebDAV Denial of Service
301625
(http://support.microsoft.com/kb/301625/EN-US/
)
Patch Available for SSI Privilege Elevation Vulnerability
304867
(http://support.microsoft.com/kb/304867/EN-US/
)
Patch Available for MIME Header Denial of Service Vulnerability
Internet Information Server 4.0The following file is available for download from the Microsoft Download Center:Collapse this image ![]() NOTE: Q301625is.exe contains the Symbols files. Release Date: August 15, 2001 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
In addition to the "superceded patches" listed above, this cumulative package contains the fixes discussed in the following Microsoft Knowledge Base article:
301625
(http://support.microsoft.com/kb/301625/EN-US/
)
Patch Available for SSI Privilege Elevation Vulnerability
May 14, 2001For more information on this release, see the following Microsoft Security Bulletin:http://www.microsoft.com/technet/security/bulletin/ms01-026.asp
(http://www.microsoft.com/technet/security/bulletin/MS01-026.mspx)
Internet Information Services 5.0To resolve this problem, either obtain the hotfix referenced in this section or the Windows 2000 Post-Service Pack 2 Security Rollup Package 1 (SRP1). For additional information about SRP1, click the article number below to view the article in the Microsoft Knowledge Base:311401
(http://support.microsoft.com/kb/311401/EN-US/
)
Windows 2000 Post-Service Pack 2 Security Rollup Package 1 (SRP1), January 2002
The following file is available for download from the Microsoft Download Center:Collapse this image ![]() Release Date: May 14, 2001 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
This cumulative package contains the following fixes:
Microsoft Security Bulletin MS01-023
(http://www.microsoft.com/technet/security/bulletin/ms01-023.mspx)
Microsoft Security Bulletin MS01-016 (http://www.microsoft.com/technet/security/bulletin/ms01-016.mspx) Microsoft Security Bulletin MS01-014 (http://www.microsoft.com/technet/security/bulletin/ms01-014.mspx) Microsoft Security Bulletin MS01-004 (http://www.microsoft.com/technet/security/bulletin/ms01-004.mspx) Microsoft Security Bulletin MS00-100 (http://www.microsoft.com/technet/security/bulletin/ms00-100.mspx) Microsoft Security Bulletin MS00-086 (http://www.microsoft.com/technet/security/bulletin/ms00-086.mspx) Microsoft Security Bulletin MS00-080 (http://www.microsoft.com/technet/security/bulletin/ms00-080.mspx) Microsoft Security Bulletin MS00-078 (http://www.microsoft.com/technet/security/bulletin/ms00-078.mspx) Microsoft Security Bulletin MS00-060 (http://www.microsoft.com/technet/security/bulletin/ms00-060.mspx) Microsoft Security Bulletin MS00-058 (http://www.microsoft.com/technet/security/bulletin/ms00-058.mspx) Microsoft Security Bulletin MS00-057 (http://www.microsoft.com/technet/security/bulletin/ms00-057.mspx) Microsoft Security Bulletin MS00-044 (http://www.microsoft.com/technet/security/bulletin/ms00-044.mspx) Microsoft Security Bulletin MS00-031 (http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx) Microsoft Security Bulletin MS00-030 (http://www.microsoft.com/technet/security/bulletin/ms00-030.mspx) Microsoft Security Bulletin MS00-023 (http://www.microsoft.com/technet/security/bulletin/ms00-023.mspx) Microsoft Security Bulletin MS00-019 (http://www.microsoft.com/technet/security/bulletin/ms00-019.mspx) Internet Information Server 4.0The following file is available for download from the Microsoft Download Center:Collapse this image ![]() NOTE: Q295534is.exe contains the Symbols files. 299444
(http://support.microsoft.com/kb/299444/EN-US/
)
Post-Windows NT 4.0 Service Pack 6a Security Rollup Package (SRP)
NOTE: This patch can be installed on systems running Windows NT 4.0 Service Pack 5 or Windows NT 4.0 Service Pack 6a. IIS is not intended for use on Windows NT Server 4.0, Terminal Server Edition, and is not supported. Microsoft recommends that customers running IIS 4.0 on Windows NT Server 4.0, Terminal Server Edition, protect their systems by uninstalling IIS 4.0.Release Date: May 14, 2001 For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base: 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
This cumulative package contains the following fixes:
Microsoft Security Bulletin MS01-004
(http://www.microsoft.com/technet/security/bulletin/ms01-004.mspx)
Microsoft Security Bulletin MS00-100 (http://www.microsoft.com/technet/security/bulletin/ms00-100.mspx) Microsoft Security Bulletin MS00-086 (http://www.microsoft.com/technet/security/bulletin/ms00-086.mspx) Microsoft Security Bulletin MS00-080 (http://www.microsoft.com/technet/security/bulletin/ms00-080.mspx) Microsoft Security Bulletin MS00-078 (http://www.microsoft.com/technet/security/bulletin/ms00-078.mspx) Microsoft Security Bulletin MS00-063 (http://www.microsoft.com/technet/security/bulletin/ms00-063.mspx) Microsoft Security Bulletin MS00-060 (http://www.microsoft.com/technet/security/bulletin/ms00-060.mspx) Microsoft Security Bulletin MS00-057 (http://www.microsoft.com/technet/security/bulletin/ms00-057.mspx) Microsoft Security Bulletin MS00-044 (http://www.microsoft.com/technet/security/bulletin/ms00-044.mspx) Microsoft Security Bulletin MS00-031 (http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx) Microsoft Security Bulletin MS00-030 (http://www.microsoft.com/technet/security/bulletin/ms00-030.mspx) Microsoft Security Bulletin MS00-023 (http://www.microsoft.com/technet/security/bulletin/ms00-023.mspx) Microsoft Security Bulletin MS00-019 (http://www.microsoft.com/technet/security/bulletin/ms00-019.mspx) Microsoft Security Bulletin MS00-018 (http://www.microsoft.com/technet/security/bulletin/ms00-018.mspx) Microsoft Security Bulletin MS99-061 (http://www.microsoft.com/technet/security/bulletin/ms99-061.mspx) Microsoft Security Bulletin MS99-058 (http://www.microsoft.com/technet/security/bulletin/ms99-058.mspx) Microsoft Security Bulletin MS99-053 (http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx) Microsoft Security Bulletin MS99-039 (http://www.microsoft.com/technet/security/bulletin/ms99-039.mspx) Microsoft Security Bulletin MS99-029 (http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx) Microsoft Security Bulletin MS99-022 (http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx) Microsoft Security Bulletin MS99-019 (http://www.microsoft.com/technet/security/bulletin/ms99-019.mspx) Microsoft Security Bulletin MS99-003 (http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx)
| Article Translations
|
Back to the top

