Joe Wilcox: My eWEEK colleague Ryan Naraine reports "serious design weaknesses" affecting Internet Information Services 7, Windows Server 2008, Windows XP and Windows Vista. IIS 7 is bundled with Windows Server 2008.
Exploit details are sketchy, but not the source: Argeniss co-founder Cesar Cerrudo.
Apparently, Cerrudo plans to share more information about the security flaws during April's Hack in the Box Security Conference. That will give Microsoft some time to research the problem before Cerrudo tells all. He plans to demonstrate zero-day exploits for elevating privileges in IIS, SQL Server and Windows Server 2008.