Home / bulletins

MS07-041 - Important: Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution (939373) - Version:1.1

Posted on 13 July 2007

Important

Severity Rating: Important - Revision Note: Bulletin Updated: additional clarification has been added explaining that the vulnerability lies in an object IIS 5.1 uses to maintain statistics on hosted applications.Summary: This important security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if an attacker sent specially crafted URL requests to a Web page hosted by Internet Information Services (IIS) 5.1 on Windows XP Professional Service Pack 2. IIS 5.1 is not part of a default install of Windows XP Professional Service Pack 2. An attacker who successfully exploited this vulnerability could take complete control of the affected system.

Link

Other versions

 

TOP