Whoops, looks like there’s a big security hole in Microsoft IIS. It’s a buffer overflow in a Web-accessible program that allows users to change their passwords remotely. The real security advisory from eEye is here.