IIS Security Issue

Akshayaa Kalyanavenkatesh 0 Reputation points
2025-03-04T06:08:06.6633333+00:00

The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes it easier for remote attackers to bypass an intended rule set via an HTTP request, aka "IIS Security Feature Bypass Vulnerability."

Above is the security issue, If I install IIS 10 version will it resolve or any other solution for this issue

User's image

Internet Information Services
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. XuDong Peng-MSFT 11,421 Reputation points Microsoft External Staff
    2025-03-04T06:59:21.82+00:00

    Hi @Akshayaa Kalyanavenkatesh,

    Above is the security issue, If I install IIS 10 version will it resolve or any other solution for this issue

    As far as I know, this is a known issue and an official security update has been released to fix it. The document lists the specific affected system versions; the remaining versions have either exceeded their support lifecycle or are not affected.

    Therefore, I think installing IIS 10 or by installing the corresponding security updates will solve this problem.

    For more details, please refer to this official doc: Vulnerability in Internet Information Services (IIS) Could Allow Security Feature Bypass (2982998).

    Best regards,

    Xudong Peng


    If the answer is the right solution, please click "Accept Answer" and kindly upvote. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.