|
Microsoft Front Page Server Extensions (FPSE), included in IIS Web Server, contain a flaw that may allow a remote attacker to execute arbitrary code. The issue is due to a sub-component in FPSE called Visual Studio Remote Application Deployment (RAD) which allows Visual InterDev users to register and un-register programming components on the IIS server. The sub-component contains an unchecked buffer that may allow an attacker to execute arbitrary code with IUSR_Machine privileges.
|