Special Notice   All Products  |   Support  |   Search  |   microsoft.com Home  
Microsoft
  Home  |   Events  |   Training  |   Downloads  |   Newsletters  |   U.S. & International  |   About Our Site  |

Microsoft
Security Bulletin

Microsoft Responds to Reports of Web Server Vulnerability

Microsoft has investigated the reports of a security flaw in its Web server software. There is no "trap door" or "back door" that would expose Web pages to users who were not authorized to see them. The rumors of a secret password that would allow access to Web page source code are false.

However, a second independent vulnerability has been reported in the same Web server software that was the subject of the initial reports. Microsoft has prepared a revised security bulletin that documents the extent of this new vulnerability as well as a procedure for eliminating it.

You should read the bulletin and follow the procedure that it describes if you are using Web servers based on:
  • Microsoft Windows NT 4.0 Option Pack (the primary distribution mechanism for Internet Information Server 4.0)
  • Personal Web Server 4.0 (ships as part of Windows 95 and Windows 98)
  • FrontPage 98 Server Extensions
Read the security bulletin at: http://www.microsoft.com/technet/security/bulletin/ms00-025.asp.



© 2000 Microsoft Corporation. All rights reserved. Terms of Use.
Last Updated: April 15, 2000