Microsoft yesterday released Microsoft Security Advisory (971492) which contains information regarding a security vulnerability that affects Internet Information Service (IIS) 5.0, 5.1 and 6.0. Microsoft describes the flaw as "Microsoft is investigating new public reports of a possible vulnerability in Microsoft Internet Information Services (IIS). An elevation of privilege vulnerability exists in the way that the WebDAV extension for IIS handles HTTP requests. An attacker could exploit this vulnerability by creating a specially crafted anonymous HTTP request to gain access to a location that typically requires authentication." Read the rest of this entry »
