Microsoft Security Advisory (971492) - Vulnerability in Internet Information Services Could Allow Elevation of Privilege

Published Tuesday, May 19, 2009 9:15 AM

Related to WEBDAV and the Anonymous account (IUSER_<>)

Microsoft is investigating new public reports of a possible vulnerability in Microsoft Internet Information Services (IIS). An elevation of privilege vulnerability exists in the way that the WebDAV extension for IIS handles HTTP requests. An attacker could exploit this vulnerability by creating a specially crafted anonymous HTTP request to gain access to a location that typically requires authentication.

We are not aware of attacks that are trying to use this vulnerability or of customer impact at this time. Microsoft is investigating the public reports.

http://www.microsoft.com/technet/security/advisory/971492.mspx

This Blog

Visitor Map

Locations of visitors to this page

Search

News

  • Beauty, n.: The power by which a woman charms a lover and terrifies a husband

Community

Archives

Syndication

Technical

General

Blogs

Me