VYPR
Unrated severityNVD Advisory· Published Oct 30, 2001· Updated Apr 16, 2026

CVE-2001-0544

CVE-2001-0544

Description

IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local users can cause IIS 5.0 to hang by installing content with an invalid MIME Content-Type header, corrupting the File Type table.

Vulnerability

In IIS 5.0, a local user can cause a denial of service by installing content that produces a specific invalid MIME Content-Type header. This corrupts the IIS File Type table, causing the web server to hang. The vulnerability exists in IIS 5.0 and is triggered by local installation of such content. [1]

Exploitation

An attacker must have local access to the IIS 5.0 server to install content that generates the invalid MIME Content-Type header. No user interaction or network access is required; the attacker can directly cause the denial of service by placing the malicious content on the server. The exact steps involve installing content with the malformed header, which then corrupts the File Type table, leading to a server hang. [1]

Impact

Successful exploitation results in a denial of service condition where the IIS 5.0 server hangs, disrupting web services. The impact is limited to availability; no information disclosure or privilege escalation is achieved. The server may need to be restarted to recover. [1]

Mitigation

Microsoft released a cumulative patch for IIS 5.0 in Security Bulletin MS01-044 (August 2001) that addresses this vulnerability. System administrators should apply the patch to prevent exploitation. No workaround is documented aside from applying the update. [1]

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.