Code Red II Worm
The Code Red II (CRII) worm was discovered August 4, 2001, and has compromised over 100,000 systems. Other than using the same mechanism as the original Code Red worm to infect vulnerable computers, Code Red II was a new and different worm. Both
worms look for systems running Microsoft IIS that have not patched the unchecked
buffer vulnerability in idq.dll or removed the ISAPI script mappings. The worm exploits the vulnerability to inject itself. Note that IIS is often installed by other applications and may be installed without the user's knowledge.
Note
Microsoft released a patch for the vulnerable idq.dll, which the Code Red and Code Red
II worms exploited. It is available at http://www.microsoft.com/technet/
treeview/default.asp?url=/technet/security/bulletin/MS01-
033.asp.