Microsoft confirms hackers are exploiting IIS server bug
Microsoft says it has evidence hackers are exploiting an unpatched bug in its server software which it announced last week. The firm says a patch is on the way, but it appears unlikely to be part of this week’s Patch Tuesday update.
The bug was officially announced last week along with details of a workaround. At that stage there were no signs of hackers taking advantage. Now, perhaps inevitably, there have been “limited attacks that use this exploit code.”
The problem involves Internet Information Services (IIS), a server system used by almost a third of websites. At first it was thought only an older edition (5.0 through 6.0, distributed with Windows 2000, Server 2003 and XP) could be attacked, allowing hackers to take control of the FTP system used for file transfers.