SHARE
Facebook X Pinterest WhatsApp

Microsoft Confirms IIS Server Security Hole

Jun 16, 1999

Microsoft Wednesday was accused of trying to downplay a security flaw in its Web
server software.

The company issued a bulletin late Tuesday about the so-called “malformed HTR request” vulnerability in Microsoft’s popular Internet Information Server 4.0 software.

According to Microsoft, the flaw could allow denial of service attacks or,
under certain conditions, could allow arbitrary code to be run on the server.

But that’s just the tip of the iceberg, according to Firas Bushnaq, CEO of
eEye, the Internet security firm that discovered the hole.

Bushnaq said Microsoft is not publicizing the fact that crackers could
exploit the flaw to take complete control over IIS servers, many of which
are hosting e-commerce sites.

“We have confirmed on numerous servers that this is exploitable. We got a
DOS prompt with system level access to the machine remotely, and other
organizations, including big security companies, have been able to
reproduce this and get system-level access.”

In its bulletin Microsoft has released information about a
work-around. The company also promised to provide a patch to eliminate the
vulnerability.

Recommended for you...

U.S. Needs to Protect Tech Leadership: Qualcomm
Rob Enderle
Apr 8, 2022
HP’s ExtendXR Service Gets an Early Lead on a Looming Metaverse Problem
Rob Enderle
Mar 5, 2022
Cisco’s Purpose Is to Improve the World. Imagine if Others Followed.
Rob Enderle
Dec 17, 2021
HP Builds an Advanced Cloud Workstation for the Metaverse
Rob Enderle
Nov 13, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.