Skip to main content

Microsoft IIS hole gives System-level access

posted onMay 2, 2001
by hitbsecnews

Strong words from the official voice of Redmond today, urging admins to patch a recently-discovered buffer overflow vulnerability in servers running IIS 5.0 on Windows 2000 Server, Windows 2000 Advanced Server and Windows 2000 Datacenter Server, make it clear how serious a security problem Microsoft has on its hands.

"Microsoft strongly urges all IIS 5.0 server administrators to install the patch immediately," a company security bulletin says.

The vulnerability was discovered less than a fortnight ago by engineers from eEye Digital Security, while upgrading a security scanner it makes called Retina.

Once upgraded to audit the .printer ISAPI (Internet Server Application Programming Interface) filter (C:WINNTSystem32msw3prt.dll), which enables Web-based control of networked printers, the Retina implementation reported a buffer overflow which eEye soon found to be exploitable.

SecurityFocus

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th