Microsoft Unleashes A Hailstorm of PatchesMicrosoft Unleashes A Hailstorm of Patches

Vendor fixes flaws in its Internet Information Services and Windows Media Services software.

George V. Hulme, Contributor

March 4, 2003

1 Min Read
information logo in a gray background | information

Microsoft on Wednesday released a batch of patches that fix security holes in several versions of its Internet Information Services software.

IIS versions 4, 5, and 5.1 are vulnerable to what is known in security circles as a cross-site scripting attack, according to Microsoft. It's a sophisticated attack that requires the attacker to lure a Web surfer to visit a specially designed Web site and open a link. The request to open the link is sent to another IIS server, and that server can send a script that would run on the user's machine and make it vulnerable.

Other IIS patches take care of flaws that can result in a denial-of-service attack in IIS versions 4 and 5; a second denial-of-service flaw that affects both versions 4 and 5; and a buffer overflow vulnerability in version 5 that allows attackers to run code of their choice on vulnerable servers.

A patch for a flaw in Windows Media Services in Windows 2000 and NT 4.0 was also released on Wednesday.

All of the patches and more information about the security vulnerabilities are available at www.microsoft.com/security.

Read more about:

20032003

About the Author

George V. Hulme

Contributor

An award winning writer and journalist, for more than 20 years George Hulme has written about business, technology, and IT security topics. He currently freelances for a wide range of publications, and is security blogger at information.com.

Never Miss a Beat: Get a snapshot of the issues affecting the IT industry straight to your inbox.

You May Also Like


More Insights