Microsoft IIS FTP Server Stack Based Overrun Vulnerability
1 Sep. 2009
Summary
Microsoft IIS servers that allow anonymous write access to the FTP server are vulnerable to a stack based overrun. IIS5 and to some degree IIS6 are susceptable.
Vulnerable Systems:
* Microsoft IIS 5
* Microsoft IIS 6
Workaround
US-CERT encourages administrators to disable anonymous write access to the FTP server to help mitigate the vulnerability, although a proper impact analysis should be performed prior to taking defensive measures. It is also possible to mitigate it by preventing people from creating directories.