Microsoft Internet Information Services (IIS) Security Feature Bypass Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A security feature bypass vulnerability exists in Microsoft Information Services (IIS) that is caused when incoming web requests are not properly compared against the "IP and domain restriction" filtering list. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The update addresses the vulnerability by modifying how inbound web requests are compared to the allow/deny list maintained by the "IP and domain restrictions" component.
Impact
- Security Restriction Bypass
System / Technologies affected
- Windows 8 and Windows 8.1
- Windows Server 2012 and Windows Server 2012 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/ms14-076.aspx
Vulnerability Identifier
Source
Related Link
Share with