Home arrow Vendor Advisories arrow Microsoft arrow MS09-020 - Important: Vulnerabilities in Internet Information Services...
Sunday, 01 August 2010
 
spacer.png, 0 kB
spacer.png, 0 kB
spacer.png, 0 kB
MS09-020 - Important: Vulnerabilities in Internet Information Services...

Severity Rating: Important - Revision Note: Bulletin published.Summary: This security update resolves one publicly disclosed vulnerability and one privately reported vulnerability in Microsoft Internet Information Services (IIS). The vulnerabilities could allow elevation of privilege if an attacker sent a specially crafted HTTP request to a Web site that requires authentication. These vulnerabilities allow an attacker to bypass the IIS configuration that specifies which type of authentication is allowed, but not the file system-based access control list (ACL) check that verifies whether a file is accessible by a given user. Successful exploitation of these vulnerabilities would still restrict the attacker to the permissions granted to the anonymous user account by the file system ACLs.

Read more at: http://www.microsoft.com/technet/security/bulletin/MS09-020.mspx?pubDate=2009-06-09

 
spacer.png, 0 kB
     

© 2010 Intellect Information Technology Pty Ltd, Melbourne, Australia.

This page was loaded in 0.065 seconds.