Skip to main content

Microsoft Windows IIS FTP Service Multiple Vulnerabilities( 14 October 2009 )

Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 4326 Views

RISK: Medium Risk

1. IIS FTP Service DoS Vulnerability

A vulnerability exists in the FTP Service in Microsoft Internet Information Services (IIS) 5.0, Microsoft Internet Information Services (IIS) 5.1, Microsoft Internet Information Services (IIS) 6.0, and Microsoft Internet Information Services (IIS) 7.0. The vulnerability could allow denial of service (DoS).

2. IIS FTP Service RCE and DoS Vulnerability

A Vulnerability exists in the FTP Service in Microsoft Internet Information Services (IIS) 5.0, Microsoft Internet Information Services (IIS) 5.1, and Microsoft Internet Information Services (IIS) 6.0. The vulnerability could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.1, IIS 6.0.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Microsoft Windows 2000
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Microsoft Internet Information Services 5.0 (FTP Service 5.0)
  • Microsoft Internet Information Services 5.1 (FTP Service 5.1)
  • Microsoft Internet Information Services 6.0 (FTP Service 6.0)
  • Microsoft Internet Information Services 7.0 (FTP Service 6.0)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link