Skip to main content

Microsoft Internet Information Services (IIS) ASP Vulnerability( 13 February 2008 )

Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 4291 Views

RISK: Medium Risk

A remote code execution vulnerability exists in the way that Internet Information Services handles input to ASP Web pages. An attacker could exploit the vulnerability by passing malicious input to a Web site's ASP page. An attacker who successfully exploited this vulnerability could then perform any actions on the IIS Server with the same rights as the Worker Process Identity (WPI), which by default is configured with Network Service account privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Internet Information Services 5.1
  • Microsoft Internet Information Services 6.0
  • Windows XP Professional
  • Windows Server 2003

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link