Follow ITProPortal:

RSS Tweet Digg

New Microsoft IIS Server Vulnerability Exposed

Security expert and researcher Soroush Dalili has warned of a new zero day vulnerability in Microsoft’s highly popular Internet Information Service (IIS) web server which could allow hackers to pass through the security barrier and insert malicious code in any machine. 

In a blog post, Dalili has categorised the threat as ‘Highly Critical’ and has communicated the need for a patch before the vulnerability gets exploited by hackers. 

Dubbing the zero day flaw as the ‘semi colon bug’, the research wrote in the security warning that IIS can execute any extension as an Active Server Page or any other executable file like .cer and  .asa.  

Explaining the bug he mentioned that malicious.asp;.jpg gets executed as an ASP file on the IIS server as “Many file uploaders protect the system by checking only the last section of the filename as its extension. And by using this vulnerability, an attacker can bypass this protection and upload a dangerous executable file on the server”. 

Meanwhile, Microsoft Corp has acknowledged the discovery of the zero-day bug and has announced via a blog post that the company was looking into the matter and that a patch will be released in near future. 



blog comments powered by Disqus

ITProPortal.com monitors all leading technology stories and rounds them up to help you save time hunting them down.

Follow ITProPortal:

RSS Tweet Digg

Owned &
operated by:

Net Communities