Microsoft KB Archive/242559

= Files on an FTP Server Are Improperly Accessed =

Article ID: 242559

Article Last Modified on 9/5/2007

-

APPLIES TO


 * Microsoft Commercial Internet System 2.5

-



This article was previously published under Q242559



SYMPTOMS
When you apply the fix referenced in the following Microsoft Knowledge Base article, there is a possibility that files located on a Microsoft FTP server can be viewed and downloaded regardless of NTFS file or folder permissions.

237987 FTP GET Does Not Work Correctly on UNC Virtual Directories

If the aforementioned fix is applied to your Internet Information Server (IIS) 4.0 computer or if you have applied a fix with the version number 0719 through 0722, it is recommended that you update your system with the security patch referenced in the "Resolution" section of this article.



RESOLUTION
A supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that are experiencing this specific problem. This fix may receive additional testing. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Commercial Internet System service pack that contains this hotfix.

To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site:

http://support.microsoft.com/default.aspx?scid=fh;EN-US;CNTACTMS

NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The typical support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

The English version of this fix should have the following file attributes or later:

  Date      Time    Version      Size    File name     Platform -  09/16/99  03:40PM 8.0.351.0   85,264   Ftpsvc2.dll   x86 09/16/99 12:39PM 8.0.351.0  150,288   Ftpsvc2.dll   Alpha This hotfix has been posted to the following Internet location as as Q242559.exe (x86):

ftp://ftp.microsoft.com/bussys/mcis/mcis-public/fixes/usa/mcis25/security/ftpsvc-fix/x86/

This hotfix has been posted to the following Internet location as as Q242559.exe (Alpha):

ftp://ftp.microsoft.com/bussys/mcis/mcis-public/fixes/usa/mcis25/security/ftpsvc-fix/alpha/



STATUS
Microsoft has confirmed that this is a problem in Commercial Internet System 2.5.



MORE INFORMATION
For related information on this problem, please visit the following Microsoft Web site:

http://www.microsoft.com/technet/security/bulletin/ms99-039.mspx

For additional security-related information about Microsoft products, please visit the following Microsoft Web site:

http://www.microsoft.com/security/

Keywords: kbbug kbfix kbhotfixserver kbqfe KB242559

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.