Security Alerts - Microsoft Internet Information Services Could Allow Remote Code Execution (MS07-041)
In this month Microsoft security bulletin, there's one important vulnerability related to IIS.
Summary:
This important security update resolves a privately reported vulnerability. This vulnerability could allow remote code execution if an attacker sent specially crafted URL requests to a Web page hosted by Internet Information Services (IIS) 5.1 on Windows XP Professional Service Pack 2. IIS 5.1 is not part of a default install of Windows XP Professional Service Pack 2. An attacker who successfully exploited this vulnerability could take complete control of the affected system.
Affected Platform:
Windows XP SP2 - IIS 5.1
Vulnerability:
Remote Code Execution
More detail...