NEWS Microsoft has issued a pair of security alerts addressing potential flaws that could make its software vulnerable to attackers. The higher-rated of the two bulletins, issued on Wednesday, includes a patch that fixes four separate vulnerabilities in Microsoft's Internet Information Services (IIS) software. That alert, rated 'important', addresses vulnerabilities that could make servers running the software vulnerable to a denial-of-service attack. "We definitely want everyone who is running IIS 4.0, 5.0 and 5.1 to install the patch," said Microsoft programme manager Stephen Toulouse. However, IIS 6 and Microsoft Windows Server 2003 are not affected by the flaws, he added. A second bulletin, rated 'moderate', addresses a vulnerability in Windows Media Services that, if exploited, could result in a denial-of-service attack. The bulletins are Microsoft's 18th and 19th security warnings of the year. Of the four issues addressed in the combination patch, the most serious vulnerability is one in the WebDav service that IIS uses for authoring. If exploited, the flaw could cause a server running IIS to stop responding to requests. That vulnerability exists in versions 5.0 and 5.1 of IIS but not in version 4.0. Two other flaws addressed by the combination patch are rated as moderate. One could lead to a denial of service, while another could allow malicious code to be run through what is known as a 'buffer overrun'. However, to be exploited, both vulnerabilities require an attacker to first upload a specific page to a web page. As for Microsoft's second bulletin, which addresses Windows Media Services, a flaw in one of the files associated with that software could allow someone to cause an IIS server to stop responding. Microsoft has taken a number of steps in recent months to try to convince more information technology managers to install its security patches. The company has set up separate email alert systems for corporate IT managers and for consumers as well as a freephone number, should customers encounter problems with any of Microsoft's patches. Toulouse said that while Microsoft tries to work quickly to address problems, it spends as much time as possible testing its fixes to make sure new flaws are not introduced. "We aren't satisfied until everyone has the patch installed," he said. "We've done a variety of things to try and communicate as broadly as we can to our customers that they need to install these updates." In addition to the two new bulletins, Microsoft updated two existing alerts, issuing a new patch for one vulnerability and updating an existing patch for a different flaw. On Tuesday, the company withdrew a security update for Windows XP, saying that it switched off internet connections for some of those who had downloaded the patch. Ian Fried writes for CNET News.com.
Further security alerts from Microsoft
Some versions of IIS affected
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
How malware threats have changed
These days, cybercriminals have four core weapons: targeted attacks, infecting websites, social networking and mobile...
-
Guide to social media use in your business
Are you on Twitter, Facebook or Google ? Even if you're not, you should know about social networking's benefits and...
-
Keeping flash drives secure with biometric authentication
People and organisations hand over their most valuable and vital personal information to government agencies. It is...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




