MICROSOFT ALERTS ON VULNERABILITY OF IIS
Microsoft made a disclosure this week about a vulnerability detected in its
Internet Information Services (IIS) and informed that it's compiling a security update to fix this issue. As a workaround solution, Microsoft recommended users can disable various elements of the exposed FTP (File Transfer Protocol) service to download & upload files.
The vulnerability in IIS allows a hacker to run arbitrary code on the server using FTP on IIS 5.0 version and execute a denial-of-service attack using FTP on IIS 5.1, 6.0, & 7.0. It is important to know that the latest 7.5 version is free from this vulnerability and it can be downloaded and installed on IIS 7.0 to shield it.
Alan Wallace, senior communications manager for Microsoft's security response communications team, announced in a statement, “Customers should be aware that the Download Center has FTP 7.5 available for
Windows Vista and
Windows Server 2008. FTP 7.5 is not vulnerable to any of these exploits.”