Microsoft IIS web server under attack from hackers
The company has said that exploit code targeting the flaw was ‘not responsibly disclosed’.

Microsoft has updated a security advisory concerning vulnerabilities in its Internet Information Services (IIS) web server, confirming that "limited" attacks were using publicly available exploit code.
The attacks are targeting flaws in the FTP service in Microsoft IIS 5.0 and could allow remote execution attacks or denial of service (DoS) attacks in IIS 5.0 as well as 5.1, 6.0 or 7.0.
Microsoft said it was aware that detailed exploit code had been published for the vulnerabilities, and was "actively monitoring this situation to keep customers informed and to provide customer guidance as necessary."
Microsoft said in the advisory: "These vulnerabilities were not responsibly disclosed to Microsoft and may put computer users at risk."
Tomorrow's Patch Tuesday has come too soon to fix the IIS vulnerabilities in question, but Microsoft said it would take the appropriate action, which could mean a security update released for a future Patch Tuesday or an out-of-cycle security update.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Mitre reveals ten worst hardware security weaknesses in 2021
News The list aims to highlight common hardware flaws to help eliminate them from product development cycles
By Rene Millman
-
New malware plants backdoor on Microsoft web server software
News IIS target of hackers looking to enter victim’s infrastructure
By Rene Millman
-
HPE warns of a critical zero-day flaw in server management software
News There's a workaround for Windows customers, but nothing for Linux admins
By Danny Bradbury
-
BBX BlackBerry Server brings security ruckus for CIOs
News Working with the new BlackBerry Server, BBX will secure enterprise data and provision enterprise apps without blocking consumer apps.
By Mary Branscombe
-
DeviceLock 7 review
Reviews Accidental or deliberate data leakage is now a major security headache for businesses. Dave Mitchell takes a look at DeviceLock 7 to see if it plugs those holes that others leave behind.
By Dave Mitchell
-
UPDATED: Kaspersky hit by cyber criminals?
News The anti-virus specialists have reportedly been beaten at their own game.
By Jennifer Scott
-
DDoS attack turns servers into bots
News A new distributed denial of service attack has been discovered that uses servers to distribute rather than PCs.
By Jennifer Scott
-
UPDATED: Hackers could take control of Microsoft's IIS server
News A flaw in IIS could allow the bad guys to come in and take control.
By Asavin Wattanajantra