Microsoft
The flaw affects XP Professional SP2, Server 2003, Vista and Server 2008
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft warns of web server flaw

Hosting providers affected by privilege elevation problem

Shaun Nichols in California, vnunet.com 21 Apr 2008
ADVERTISEMENT

Microsoft is investigating a newly reported flaw that could put websites at risk of attack.

The company has issued an advisory on the vulnerability, which affects Windows XP Professional SP2, Windows Server 2003, Windows Vista and Windows Server 2008.

The problem exists in Windows' handling of code within its Internet Information Services (IIS) and SQL Server.

If exploited, the vulnerability could allow a user to elevate access privileges to that of the LocalSystem administration tool.

Microsoft warned that companies that make extensive use of user-provided code, such as site hosts, are especially vulnerable.

Microsoft has yet to receive any reports of the vulnerability being targeted, but security experts have already warned of a possible attack.

"The vulnerability is limited to a local privilege escalation, but IIS' susceptibility is concerning," wrote McAfee researcher Karthik Raman.

"The web server is widely used on the internet, and is a top pick by web-hosting providers. We might see web-hosting providers targeted, and their clients' websites breached."

Microsoft is still investigating the reports and will make a decision on whether to issue a patch immediately or wait until its next scheduled security update on 13 May.

See also:

Microsoft/YahooAd deal may keep Microsoft at bay  18 Apr 2008
Windows VistaDon't wait for Windows 7, says Forrester  18 Apr 2008
MicrosoftCompany courts OEMs and amateur developers  16 Apr 2008
MicrosoftMobile software developer to be integrated with Mobile Communications Business  16 Apr 2008

All Bugs & Fixes
Tags: Microsoft, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities