Microsoft IIS contains a flaw in the ODBC tool that is triggered when an unauthenticated remote attacker uses ctguestb.idc to initialize a DSN. While this issue may not be severe by itself, this can be used in conjunction with other IIS vulnerabilities to gain escalated privileges.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Solution:
Workaround
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: do not use MS Jet ODBC drivers for any DSN.