Microsoft's five critical updates won't include IIS

Article

Microsoft's five critical updates won't include IIS

Microsoft said it plans to release five critical patches next week, repairing flaws in Microsoft Windows that could be remotely attacked by hackers.

In its advance notification issued Thursday, the software giant said two of the updates require mandatory restarts.

    Requires Free Membership to View

    SearchSecurity.co.UK members gain immediate and unlimited access to breaking UK industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.co.UK today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.co.uk you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.co.uk is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

The patches affect Windows 2000, XP and Vista, as well as all three of Microsoft's server platforms 2000, 2003 and 2008.

Microsoft said it won't have a patch ready for a vulnerability affecting the FTP Service in Microsoft Internet Information Services 5.0. A security advisory was issued earlier this week warning users about the flaw.

Exploit code was published, but so far there have been no reported ongoing attacks in the wild, Microsoft said. The exploit code began circulating on the Milw0rm site on Monday.

While a patch is being tested, Microsoft issued recommendations alerting customers to a workaround. Companies can modify the NTFS file system permissions to bar FTP users from creating directories.