All the latest UK technology news, reviews and analysis

Microsoft warns of new flaw in Internet Information Server

by Shaun Nichols

20 May 2009

Comment: 1

  • Tweet this
Microsoft bugs
Microsoft has warned of a new vulnerability in IIS

Microsoft has issued a security advisory about a new vulnerability in Windows Internet Information Server (IIS).

IIS is a component used primarily by Windows Server systems to provide web hosting services. It is also included in Windows XP Professional, as well as the Business, Enterprise and Ultimate editions of Windows Vista.

Microsoft said that the vulnerability could allow an attacker to gain elevated privileges on a targeted server, possibly allowing the attacker to access and edit data.

The flaw affects IIS versions 4.0, 5.0 and 6.0. The newest version, IIS 7.0, is not believed to be vulnerable. No active attacks targeting the flaw have been reported.

Microsoft said that the vulnerability is exposed when an attacker sends a specially-crafted HTTP request file to the targeted server. Once exploited, the attacker could bypass authentication requirements and access the system with anonymous account clearance.

The company noted that the vulnerability is limited to the extent to which administrators have set access for anonymous users. By limiting access and preventing write clearance for the accounts - a default setting for most IIS systems - the danger of attack can be mitigated.

Many IIS 6.0 users should also be protected, as the vulnerable WebDAV component is disabled in those systems by default.

Microsoft did not say when a fix for the vulnerability could be expected. The company's next scheduled security update is 9 June.

This is not the first time that vulnerabilities in IIS have gained attention. In 2001, the component was the main target of the Code Red and Code Blue worms.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

32%

1%

10%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Grad BI Consultant

Implementation Consultant - Business Intelligence Software...

SQL Server DBA, ETL, SSIS, Financial

SQL Server DBA, ETL, SSIS, Datawarehousing, Financial...

Senior DB2 DBA

Job description *Customer facing: should be able to...

PHP / MySQL / Zend Framework Developer - Chelmsford

PHP / MySQL / Zend Framework Developer - Chelmsford...

To send to more than one email address, simply separate each address with a comma.