Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-016