|
|
ITSS-Advisory : MEDIUM : Microsoft : IIS 6 with WebDav (Sharepoint) vulnerability: Potentially unauthenticated remote access and code executionTHREAT LEVEL INFORMATION
AFFECTED PLATFORMS WebDAV is not enabled by default on IIS 6.0 in the default configuration.Unless WebDAV has been enabled by an administrator on these systems, the vulnerability is present, but not exposed. ACTION Original Bulletin: Microsoft has released a bulletin regarding the new IIS vulnerabilities. It is available at: While a fix is not yet available, the vulnerability does not bypass underlying file system access lists and so the issue can be further mitigated by applying strict access controls for the anonymous web user. http://support.microsoft.com/?id=271071 Administrators of affected computer systems are advised to review the References: |
| Date Created: 14 May 2009 |
© The University of Melbourne 1994-2003 |