The Register®

Original URL: http://www.theregister.co.uk/2001/08/16/iis_252_berpatch_claims/

IIS über-patch claims to wipe out all old Web server flaws

And five fresh bugs too

By John Leyden

Posted in Security, 16th August 2001 11:25 GMT

Free whitepaper – Dell IT infrastructure services brochure

Microsoft has released an über-patch that aims to address all the previously announced vulnerabilities in its IIS Web server software, and a few more besides.

The cumulative patch (http://www.microsoft.com/technet/security/bulletin/ms01-044.asp) includes the functionality of all security patches released to date for IIS 5.0, and all patches released for IIS 4.0 since Windows NT 4.0 Service Pack 5.

Microsoft has promised that the cumulative patch eliminates the "side effects" of the previous IIS cumulative patch, which have led some admins to defer the installation of the fix even while the FBI warned the Russian Mafia was exploiting flaws with IIS to raid online banks (http://www.theregister.co.uk/content/archive/17456.html).

Apparently it took the outbreak of Code Red for Microsoft to take anything approaching decisive in making its easier for admins to guard against the many flaws on IIS.

The update, which amounts to a point release for both IIS 4 and IIS 5, also addresses five previously undisclosed vulnerabilities with IIS, which could result in either denial of service or privilege elevation.

That's quite a list and it makes you wonder what other bugs the notoriously flaky IIS harbours.

When Microsoft next releases a Web server product we hope it sees the value of a comprehensive security audit BEFORE the product is released. We can but hope... ®

External Links

MS bulletin: cumulative patch for IIS (http://www.microsoft.com/technet/security/bulletin/ms01-044.asp)

Related Stories

MS internal network whacked by Code Red (http://www.theregister.co.uk/content/55/20937.html)
Russian Mafia uses NT flaws to raid Internet banks (http://www.theregister.co.uk/content/archive/17456.html)
Code Red and the Cisco side effect (http://www.theregister.co.uk/content/55/20990.html)
Son of Code Red is born (http://www.theregister.co.uk/content/55/20841.html)
Internet survives Code Red (http://www.theregister.co.uk/content/4/20546.html)
IIS worm made to packet Whitehouse.gov (http://www.theregister.co.uk/content/55/20474.html)
MS hacked once, twice, three, FOUR times (http://www.theregister.co.uk/content/archive/19915.html)
MS confronts another IIS system-level hole (http://www.theregister.co.uk/content/archive/19794.html)
Yet another IIS exploit reported (http://www.theregister.co.uk/content/archive/18978.html)
Microsoft IIS hole gives System-level access (http://www.theregister.co.uk/content/archive/19794.html)