UPDATED: Hackers could take control of Microsoft's IIS server
A flaw in IIS could allow the bad guys to come in and take control.
There is a warning of a vulnerability in Microsoft's Internet Information Services (IIS) web server, which could allow hackers to execute code and take control.
The United States Emergency Readiness Team (US-CERT) had posted an advisory about the issue, alerting users to a problem in the Microsoft IIS FTP service.
It was reported that the exploit code was originally posted on the Milw0rm site on Monday, which could soon make real-world attacks a possibility.
IIS 5 and IIS 6 are vulnerable. IIS is the second most popular web server behind Apache, according to statistics from July.
"By issuing an FT NLST (NAME LIST) command on a specially-named directory, an attacker may cause a stack buffer overflow," US-CERT's warning said.
"The attacker can create the specially-named directory if FTP is configured to allow write access using Anonymous account of a another account that is available to the attacker."
Microsoft confirmed the vulnerability in a security advisory, but stressed that it had not seen active attacks using the exploit code.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
-
Gartner: here's how AI will remake business in the next three yearsNews You've got three years to prep for these new attacks and challenges thanks to AI, says Gartner
-
Two-thirds of cyber threats still require manual resolutionNews Security teams are spending most of their time on reactive alert triage and manual data gathering, with little left over for proactive threat hunting
-
Mitre reveals ten worst hardware security weaknesses in 2021News The list aims to highlight common hardware flaws to help eliminate them from product development cycles
-
New malware plants backdoor on Microsoft web server softwareNews IIS target of hackers looking to enter victim’s infrastructure
-
HPE warns of a critical zero-day flaw in server management softwareNews There's a workaround for Windows customers, but nothing for Linux admins
-
BBX BlackBerry Server brings security ruckus for CIOsNews Working with the new BlackBerry Server, BBX will secure enterprise data and provision enterprise apps without blocking consumer apps.
-
DeviceLock 7 reviewReviews Accidental or deliberate data leakage is now a major security headache for businesses. Dave Mitchell takes a look at DeviceLock 7 to see if it plugs those holes that others leave behind.
-
UPDATED: Kaspersky hit by cyber criminals?News The anti-virus specialists have reportedly been beaten at their own game.
-
DDoS attack turns servers into botsNews A new distributed denial of service attack has been discovered that uses servers to distribute rather than PCs.
-
Microsoft IIS web server under attack from hackersNews The company has said that exploit code targeting the flaw was ‘not responsibly disclosed’.