![]() This update applies, with the same severity rating, to supported editions of Windows Server 2008 or Windows Server 2008 R2 as indicated, whether or not installed using the Server Core installation option. Internet Information Services 5.1 (KB2290570) Internet Information Services Authentication Internet Information Services 7.5* (KB2271195) Internet Information Services 7.5 (KB2271195) Windows Server 2008 R2 for Itanium-based Systems Internet Information Services 7.5* (KB2124261) Windows Server 2008 R2 for 圆4-based Systems Internet Information Services 7.5 (KB2124261) Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2 Windows Server 2008 for 圆4-based Systems and Windows Server 2008 for 圆4-based Systems Service Pack 2 Internet Information Services 7.0* (KB2124261) Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2 ![]() Windows Vista 圆4 Edition Service Pack 1 and Windows Vista 圆4 Edition Service Pack 2 ![]() Internet Information Services 7.0 (KB2124261) ![]() Windows Vista Service Pack 1 and Windows Vista Service Pack 2 Windows Server 2003 with SP2 for Itanium-based Systems Windows Server 2003 圆4 Edition Service Pack 2 Internet Information Services 6.0 (KB2124261) Windows XP Professional 圆4 Edition Service Pack 2 Internet Information Services 5.1 (KB2124261) To determine the support life cycle for your software version or edition, visit Microsoft Support Lifecycle. Other versions or editions are either past their support life cycle or are not affected. The following software have been tested to determine which versions or editions are affected. When currently known issues and recommended solutions pertain only to specific releases of this software, this article provides links to further articles. The article also documents recommended solutions for these issues. Microsoft Knowledge Base Article 2267960 documents the currently known issues that customers may experience when installing this security update. See also the section, Detection and Deployment Tools and Guidance, later in this bulletin. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.įor administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update at the earliest opportunity using update management software, or by checking for updates using the Microsoft Update service. Customers who have not enabled automatic updating need to check for updates and install this update manually. Recommendation. The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information. ![]() The security update addresses the vulnerabilities by modifying the way that IIS handles specially crafted HTTP requests. For more information, see the subsection, Affected and Non-Affected Software, in this section. This security update is rated Important for IIS 5.1, IIS 6.0, IIS 7.0, and IIS 7.5. An attacker who successfully exploited this vulnerability could take complete control of an affected system. The most severe of these vulnerabilities could allow remote code execution if a client sends a specially crafted HTTP request to the server. This security update resolves two privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Information Services (IIS). Version: 1.0 General Information Executive Summary Security Bulletin Microsoft Security Bulletin MS10-065 - Important Vulnerabilities in Microsoft Internet Information Services (IIS) Could Allow Remote Code Execution (2267960) ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |