26 Dec 2009
Security experts are warning of a highly critical new zero day vulnerability in Microsoft’s popular Internet Information Services (IIS) web server product which could allow hackers to bypass existing security measures and upload malicious code to any affected machine.
Security researcher Soroush Dalili warned in a research note that the vulnerability affects IIS 6 and earlier versions, although IIS 7 has yet to be tested and version 7.5 is safe.
“IIS can execute any extension as an Active Server Page or any other executable extension. For instance “malicious.asp;.jpg” is executed as an ASP file on the server,” he explained.
"Many file uploaders protect the system by checking only the last section of the filename as its extension. And by using this vulnerability, an attacker can bypass this protection and upload a dangerous executable file on the server.”
Vulnerability database firm Secunia rated the flaw as “less critical” – only the second out of a potential five-grade security rating system – but Dalili maintained the impact of the bug is highly critical.
“Impact of this vulnerability is absolutely high as an attacker can bypass file extension protections by using a semi‐colon after an executable extension such as “.asp”, “.cer”, “.asa”, and so on,” he wrote.
“Many web applications are vulnerable against file uploading attacks because of this weakness of IIS.”
According to reports Microsoft researchers are investigating the vulnerability.
This is not the first time that IIS has been hit by security problems. Back in September Microsoft issued a security advisory warning of a vulnerability in the File Transfer Protocol (FTP) service in IIS 5.0, 5.1 and 6.0 which could allow remote code execution.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is a well established, non profit organisation;...
PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...
HEAD OF DIGITAL - London - £80-95K + Excellent Bens...
Agile C# Developer - (North London) £55,000 - £65,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?