Microsoft widens IIS vulnerability warning

Security

Microsoft has widened the scope of a security advisory concerning vulnerabilities in the FTP service in Internet Information Services (IIS). The versions shipping with Vista and Server 2008 are now known to be affected as well as those in older versions of Windows.

Last week, Microsoft disclosed the existence of a flaw in the FTP component of IIS that could allow remote code execution or denial of service attacks.

At the time, IIS versions 5 and 6 were said to be affected.

Microsoft now warns that IIS 7.0 is also vulnerable if it is running FTP Service 6.0, but not if it has been updated with FTP Service 7.5 (as shipped with Windows 7 and Server 2008 R2).

According to Microsoft's advisory, remote code execution is possible on IIS 5.0, but exploits are limited to denial of service attacks on IIS IIS 5.1 and later.

IIS 5.0 is part of Windows 2000.

The remote code execution attack on IIS 5.0 works by creating a long and maliciously crafted directory name, and could therefore be avoided by denying the right to create directories to untrusted users.

However, a publicly available denial of service attack on the FTP service only requires an untrusted user to have read access.

Microsoft suggests disabling the FTP service in order to "completely block the known attack vector or any variations thereof."

A patch for the issue is under development. Microsoft officials have indicated that it may be released as an out-of-cycle update as opposed to waiting for October's Patch Tuesday.

Please enable JavaScript in your browser to post your comment!

SPONSORED PRESS RELEASES

Websense Security Labs Reports ‘User Trust’ Targeted Attacks; Over 1 in 10 ‘Top Search’ Results Categorised as Malware; Increased Focus on Web 2.0
Websense, Inc. today revealed the findings from its bi-annual research report: Websense Security Labs, State of Internet Security, Q3-Q4 2009.

Featured IT jobs

A varied DBA role that involves multitasking in a dynamic software development environment dealing with challenging customer needs on a daily basis.
Skills Tags:   Linux  Oracle  UAT
A position has just become available for experienced Program/Project Manager to join a large organisation on a major Data Centre upgrade....
Skills Tags:   SAP
URGENT! Experienced BDM needed for senior sales role in Melbourne - must have ITSM consultancy sales experience.
Skills Tags:   C  Development  EDI  IT
CRITICAL INCIDENT COORDINATOR - 24 x 7 shifts - 3 month CONTRACT ONLY...
Skills Tags:   Excel  IT  ITIL  Management  Reporting

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases