CVE-2001-0544
Description
IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Local users can cause IIS 5.0 to hang by installing content with an invalid MIME Content-Type header, corrupting the File Type table.
Vulnerability
In IIS 5.0, a local user can cause a denial of service by installing content that produces a specific invalid MIME Content-Type header. This corrupts the IIS File Type table, causing the web server to hang. The vulnerability exists in IIS 5.0 and is triggered by local installation of such content. [1]
Exploitation
An attacker must have local access to the IIS 5.0 server to install content that generates the invalid MIME Content-Type header. No user interaction or network access is required; the attacker can directly cause the denial of service by placing the malicious content on the server. The exact steps involve installing content with the malformed header, which then corrupts the File Type table, leading to a server hang. [1]
Impact
Successful exploitation results in a denial of service condition where the IIS 5.0 server hangs, disrupting web services. The impact is limited to availability; no information disclosure or privilege escalation is achieved. The server may need to be restarted to recover. [1]
Mitigation
Microsoft released a cumulative patch for IIS 5.0 in Security Bulletin MS01-044 (August 2001) that addresses this vulnerability. System administrators should apply the patch to prevent exploitation. No workaround is documented aside from applying the update. [1]
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.