Schweregrad:: Hoch
  CVE Kennungen:: CVE-2014-4078
  Hinweisdatum: 14 November 2014

  Beschreibung

This update resolves a security bypass feature that exists in Microsoft Information Services (IIS) versions 8.0 and 8.5. The update fixes the vulnerability specifically in how inbound requests are processed against a list of IPs and domains that are to be allowed or denied.

  Lösungen

  Betroffene Software und Version:

  • Windows 8 for 32-bit Systems
  • Windows 8 for x64-based Systems
  • Windows 8.1 for 32-bit Systems
  • Windows 8.1 for x64-based Systems
  • Windows Server 2012
  • Windows Server 2012 R2