Code Red was the 2001 worm that exploited Microsoft IIS servers.
The worm used a buffer-overflow vulnerability in Microsoft Internet Information Services, the company’s web-server software. Once it compromised a vulnerable server, Code Red scanned for other systems to infect, allowing the outbreak to spread rapidly across the Internet. It also defaced some websites with the message “Hacked By Chinese!” and included a denial-of-service routine aimed at a White House web address.
Code Red was first observed in July 2001, and a second variant, Code Red II, appeared soon afterward. Microsoft had issued a security patch before the outbreak, but many administrators had not installed it.
Code Red is often confused with later worms such as Nimda and SQL Slammer. Those outbreaks used different vulnerabilities and appeared at different times. The incident became a prominent example of how unpatched Internet-facing servers can turn a single software flaw into a global security event.