CyberNews researchers say they have found more than two million web servers running on outdated, unmaintained and vulnerable versions of the Microsoft Internet Information Services web server. Since legacy versions of IIS are no longer supported by Microsoft, they are open to malware threats that can even extract visitor data.
Microsoft IIS is the third most popular web server software in the world, with more than 50 million web sites using it, with a market share of approximately 12%. This means that more than a tenth of the websites are compromised by being hosted on servers with outdated hardware.
Many websites and servers do not have up-to-date security
Earlier versions of IIS from 7.5 onwards are no longer compatible with Microsoft services or supported in case of vulnerabilities. Cybernews identified five different versions and subversions of IIS that were not maintained and had publicly known vulnerabilities. Although most turned out to be honeypots, more than two million were found serving genuine use cases.
While all legacy versions of IIS were susceptible to attack, version 7.0 with 17 known vulnerabilities emerged as the most damaging. This version was found to be running on more than 47.000 web servers. After further investigation, with more than 679.000 vulnerable IIS servers, China emerged as the country with the most susceptible installations. The US ranked second with more than 581.000 unprotected IIS servers.
Cybernews' Mantas Sasnauskas claims that the situation is further exacerbated by the fact that web servers hosting agency websites would also be using outdated versions of IIS, and unknowingly. Without a doubt, it is a very high number of servers and websites that do not have security support, either due to neglect or not having a technical team aware of web needs.
Source: TechRadar

