ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Server platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Microsoft patches ten IIS vulnerabilities

John McCormick

Published: 29 Apr 2002 13:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

If you have a Web server running IIS on Windows NT 4.0 or Windows 2000 (or even Windows XP), you've got some new security problems to deal with. In what can only be viewed as a bad week for Microsoft, the company recently disclosed that a full double handful of ten formerly unpatched vulnerabilities exist in Internet Information Server (IIS)--and several of them have been rated as critical threats.

Some of the vulnerabilities are buffer overruns that can allow attackers to run arbitrary code on the server or to open the servers to host, or be the target of, denial of service attacks. Other flaws are less critical but could still cause damage.

If you're running almost any version of IIS, you need to update it with the latest patches form Microsoft.

In MS02-018, which describes these 10 vulnerabilities and the associated patches, Microsoft indicates the single exception. "Beta versions of .NET Server after Build 3605 contain fixes for all of the vulnerabilities affecting IIS 6.0. As discussed in the [MS02-018] FAQ, Microsoft is working directly with the small number of customers who are using the .NET Server beta version in production environments to provide immediate remediation for them.

Risk levels--low to critical

Since at least three of these vulnerabilities affecting IIS 4.0, IIS 5.0, and IIS 5.1 are rated critical by Microsoft, the cumulative patches are very important unless you have installed IIS Lockdown Tool according to best practices and don't need the services that Lockdown disables.

Applicability

As usual, Microsoft warns that the company does not test or report on vulnerabilities in any older versions of software that the company no longer supports.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
96 out of 178 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Exciting AS400 Operator/Suport role - NW London (Middlesex)

Good understanding of AS/400 required and some Windows NT/200 and LAN/WAN experience needed. Would suit anyone who is looking for an opportunity to ...

CRM Technical Project Manager

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

IT Help Desk Analyst

Ability to resolve conflict directly or through escalation - Knowledge of IT systems Windows NT/XP. To update the call log regularly and amend the ...