Skip to main content

Microsoft Internet Information Services (IIS) File Change Notification Vulnerability ( 13 February 2008 )

Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 4302 Views

RISK: Medium Risk

A local elevation of privilege vulnerability exists in the way that the Internet Information Service handles file change notifications in the FTPRoot, NNTPFile\Root, and WWWRoot folders. An attacker who successfully exploited this vulnerability could execute arbitrary code in the context of local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Microsoft Internet Information Services 5.0
  • Microsoft Internet Information Services 5.1
  • Microsoft Internet Information Services 6.0
  • Microsoft Internet Information Services 7.0
  • Microsoft Windows 2000
  • Windows XP Professional
  • Windows Server 2003
  • Windows Vista

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link