Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.
Use Microsoft vendor hub and Index Server product page to widen CVE-2001-0500 into its surrounding weakness, vendor, and product context.
Compare it with CVE-1999-1011, CVE-2001-0244 and CVE-1999-1397 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.