Microsoft has revealed that hackers are already exploiting newly disclosed vulnerabilities in its Internet Information Services (IIS) web server software.
Exploit code for the first flaw was posted on Monday, which would allow hackers to remotely take control of an IIS 5.0 server. New code was then posted on Thursday which takes advantage of vulnerabilities in IIS 5.0, IIS 5.1, IIS 6.0 and IIS 7.0 to allow hackers to launch denial of service attacks against these systems, as long as they are running the FTP Service, said Microsoft.
Redmond was forced to update its security advisory warning that it is now seeing “limited attacks that use this exploit code”.
“Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary,” the advisory continued.
Although Microsoft is due to release its September security updates on patch Tuesday next week, it is widely believed that the new vulnerabilities were disclosed to recently for the Redmond security team to be able to deliver a working fix in time.
In a blog posting, Microsoft blamed the current, albeit limited, attacks on the fact that the original vulnerabilities were published on the internet before the firm had a chance to work on a fix.
“We continue to encourage responsible disclosure of vulnerabilities,” the post continued.
“ We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.”
Hackers already exploiting IIS flaws
By
Phil Muncaster
on Sep 7, 2009 8:09AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Channel can help lead customers to boosting workplace wellbeing with professional headsets

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program

Build cybersecurity capability with award winning Fortinet training from Ingram Micro

Tech For Good program gives purpose and strong business outcomes

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers
Sponsored Whitepapers
_page-0001.jpg&w=100&c=1&s=0)
F5’s 2025 Report: Unlocking AI Success by Conquering App & API Complexity

Driving Innovation and Sustainability through Hybrid IT and AI Solutions

Easing the burden of Microsoft CSP management
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan