CVE-2002-1973

Microsoft Foundation Class Library - Buffer Overflow in CHttpServer::OnParseError via Long Query String

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1973. PoCs published by Matthew Murphy.

AI-analyzed exploit summary This exploit demonstrates a heap overflow vulnerability in the Microsoft Foundation Class (MFC) ISAPI framework by sending a malformed HTTP POST request with a misleading Content-Length header. It targets servers using vulnerable MFC ISAPI extensions, leading to a denial of service (DoS) condition.

Description

Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matthew Murphy · cremotewindows
https://www.exploit-db.com/exploits/21601

This exploit demonstrates a heap overflow vulnerability in the Microsoft Foundation Class (MFC) ISAPI framework by sending a malformed HTTP POST request with a misleading Content-Length header. It targets servers using vulnerable MFC ISAPI extensions, leading to a denial of service (DoS) condition.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Foundation Class Library (MFC) ISAPI Framework (versions with vulnerable ISAPI class)
No auth needed
Prerequisites: Network access to the target server · Target server running an application compiled with vulnerable MFC ISAPI classes
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B216562
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/9529
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5188
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B310649
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-07/0082.html
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-07/0135.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-07/0144.html

Scores

EPSS 0.4005
EPSS Percentile 98.4%

Details

Status published
Products (2)
microsoft/foundation_class_library 7.0
working_resources_inc./badblue personal_1.7.3
Published Dec 31, 2002
Tracked Since Feb 18, 2026