Privilege Escalation Vulnerability in Internet Information Services - MS08-005ID: oval:org.secpod.oval:def:2654 | Date: (C)2011-11-02 (M)2022-10-10 |
Class: PATCH | Family: windows |
The host is missing an important security update according to Microsoft security bulletin, MS08-005. The update is required to fix privilege escalation vulnerability. A flaw is present in Internet Information Services (IIS), which fails to handle file change notifications in the FTPRoot, NNTPFile\Root, and WWWRoot folders. Successful exploitation could allow an attacker to install programs, view, change, or delete data or create new accounts with full user rights.
Platform: |
Microsoft Windows 2000 |
Microsoft Windows Server 2003 |
Microsoft Windows Vista |
Microsoft Windows XP |
Product: |
Microsoft Internet Information Server (IIS) 5.0 |
Microsoft Internet Information Server (IIS) 5.1 |
Microsoft Internet Information Server (IIS) 6.0 |
Microsoft Internet Information Server (IIS) 7.0 |