Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Server Products

December 28th, 2009, 09:54 GMT · By

Microsoft Confirms 0-Day IIS Security Vulnerability

SHARE:

Adjust text size:


Windows Server 2003
Enlarge picture
Microsoft has confirmed officially a zero-day security vulnerability affecting Internet Information Services (IIS). The security hole was initially reported just ahead of Christmas on December 23rd, and the Redmond company provided the first response at the end of the past week. So far, the issue in question affects version 6 of IIS on a fully patched Windows Server 2003 R2 SP2; however, additional IIS releases might also be impacted. Jerry Bryant, Microsoft security program manager, notes that Microsoft is aware of the problem and that investigation into the matter has already been kicked off. At the same time, Bryant assured customers running IIS that it hasn’t detected any active attacks in the wild targeting the new 0-day flaw.

“Our initial assessment shows that the IIS web server must be in a non-default, unsafe configuration in order to be vulnerable. An attacker would have to be authenticated and have write access to a directory on the web server with execute permissions which does not align with best practices or guidance Microsoft provides for secure server configuration. Customers using out of the box configurations and who follow security best practices are at reduced risk of being impacted by issues like this,” Bryant explained.

The vulnerability identified in Microsoft Internet Information Services (IIS) involves the incorrect manner in which the server deals with files with multiple extensions. As long as the multiple extensions are divided by the ";" character, the IIS server handles them as ASP files. A possible attacks scenario could be based on an exploit constructed out of malformed executables. Any malicious files uploaded to a vulnerable web server would circumvent any file extension protections and restrictions in place.

“Once we’re done investigating, we will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves,” Bryant added. “This vulnerability was not responsibly disclosed to Microsoft and may put customers at risk. We continue to encourage responsible disclosure of vulnerabilities as we believe reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.”

Microsoft is currently working on providing a patch, but for the time being, server administrators can make sure that their deployments respect the IIS 6.0 Security Best Practices provided by the company. Configuring a secure IIS server means that customers can at least mitigate the risk until a security update will be offered.

TELL US WHAT YOU THINK:

3,742 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Fix Windows 7’s 'Search programs and files' Incorrect Results

Download Windows PowerShell 2.0 Software Development Kit (SDK)

Corrupted Media Files in Windows 7 Can Generate High CPU Usage

Download Free Codename Dublin Tutorials

Forefront Unified Access Gateway 2010 Available for Download

READER COMMENTS:


Comment #1 by: anon on 28 Dec 2009, 17:34 UTC reply to this comment

This is worse than a zero-day vulnerability. We are assessing our IIS Servers, and we already have found month-old files with the .asp;.jpg extension.

Looks like hackers have known about this for quite some time.

This is much more critical than the Secunia "moderate" rating, as arbitrary code can be easily uploaded and executed.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM