Affected Versions:
Microsoft IIS 7.5 vulnerability description:
Microsoft Internet Information Service (IIS) is a network information server that comes with Microsoft Windows, which includes the HTTP service function.
For IIS servers with FastCGI enabled, remote attackers can trigger buffer overflow by submitting specially crafted HTTP requests, resulting in arbitrary code execution. <* Reference
Http://secunia.com/advisories/41375/
Http://www.us-cert.gov/cas/techalerts/TA10-257A.html
Http://www.microsoft.com/technet/security/bulletin/MS10-065.mspx? Pf = true
*>
Temporary solution:
* Disable FastCGI.
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS10-065) and patches for this:
MS10-065: Vulnerabilities in Microsoft Internet Information Services (IIS) cocould Allow Remote Code Execution (2267960)
Link: http://www.microsoft.com/technet/security/bulletin/MS10-065.mspx? Pf = true