How the IIS vulnerability (Security Advisory 971492) affects Exchange 2003

213
vote

Microsoft released recently Security Advisory 971492, which alerts for a vulnerability in Internet Information Services (IIS) 6.0, 5.1 and 5.0 (7.0 is not affected), that can allow elevation of privilege.

The vulnerability only occurs when WebDAV is enabled. Since Exchange Server 2003 uses WebDAV to service users, these servers are potentially at risk.

To find out whether a specific server is using WebDAV or whether it’s not, you can use the method Jane Lewis describes on her blog.
Continue reading here....