Skip to main content

Microsoft downplays IIS security vulnerability talk

posted onDecember 30, 2009
by hitbsecnews

Microsoft is downplaying talk of a zero-day bug in Internet Information Services (IIS).

Last week, reports began to circulate of a security vulnerability in IIS. The issue was due to the way IIS 6 handles semicolons in URLs. However Microsoft contends that because IIS must be in an unsecure configuration, the handling of semicolons is essentially besides the point.

“The key in this is...for the scenario to work, the IIS server must already be configured to allow both “write” and “execute” privileges on the same directory,” blogged Christopher Budd, communications lead for Microsoft Security Response Center. “This is not the default configuration for IIS and is contrary to all of our published best practices. Quite simply, an IIS server configured in this manner is inherently vulnerable to attack."

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th