The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6858
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0336
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026