Microsoft IIS web server under attack from hackers
The company has said that exploit code targeting the flaw was ‘not responsibly disclosed’.

Microsoft has updated a security advisory concerning vulnerabilities in its Internet Information Services (IIS) web server, confirming that "limited" attacks were using publicly available exploit code.
The attacks are targeting flaws in the FTP service in Microsoft IIS 5.0 and could allow remote execution attacks or denial of service (DoS) attacks in IIS 5.0 as well as 5.1, 6.0 or 7.0.
Microsoft said it was aware that detailed exploit code had been published for the vulnerabilities, and was "actively monitoring this situation to keep customers informed and to provide customer guidance as necessary."
Microsoft said in the advisory: "These vulnerabilities were not responsibly disclosed to Microsoft and may put computer users at risk."
Tomorrow's Patch Tuesday has come too soon to fix the IIS vulnerabilities in question, but Microsoft said it would take the appropriate action, which could mean a security update released for a future Patch Tuesday or an out-of-cycle security update.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
OpenAI just launched 'Codex', a new AI agent for software engineering
News OpenAI has unveiled the launch of a new AI agent, dubbed 'Codex', aimed specifically at supporting software engineering tasks.
-
Acer's new Swift Edge 14 AI is a MacBook Air killer
News Acer's new Swift Edge 14 AI is an ultra-lightweight, compact productivity powerhouse.
-
Mitre reveals ten worst hardware security weaknesses in 2021
News The list aims to highlight common hardware flaws to help eliminate them from product development cycles
-
New malware plants backdoor on Microsoft web server software
News IIS target of hackers looking to enter victim’s infrastructure
-
HPE warns of a critical zero-day flaw in server management software
News There's a workaround for Windows customers, but nothing for Linux admins
-
BBX BlackBerry Server brings security ruckus for CIOs
News Working with the new BlackBerry Server, BBX will secure enterprise data and provision enterprise apps without blocking consumer apps.
-
DeviceLock 7 review
Reviews Accidental or deliberate data leakage is now a major security headache for businesses. Dave Mitchell takes a look at DeviceLock 7 to see if it plugs those holes that others leave behind.
-
UPDATED: Kaspersky hit by cyber criminals?
News The anti-virus specialists have reportedly been beaten at their own game.
-
DDoS attack turns servers into bots
News A new distributed denial of service attack has been discovered that uses servers to distribute rather than PCs.
-
UPDATED: Hackers could take control of Microsoft's IIS server
News A flaw in IIS could allow the bad guys to come in and take control.