Georgi Guninski has discovered a security issue that he believes in present in Internet Information Server 5.0. By using specifically designed URLs a malicious attacker could retrieve specific content. One such scenario could lead to cookie stealing.
The .htm file specified must exist in order for this to work.
Microsoft has confirmed that this vulnerability exists but says that the problem is present in Microsoft Index Server not Internet Information Server. Microsoft is currently testing a patch and will release a security bulletin and patch soon.