Microsoft disclosed a critical vulnerability (MS15-034) affecting their web server IIS that allows for remote, unauthenticated denial of service and remote code execution.
This security update is rated Critical for all supported editions of Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows 8.1 and Windows Server 2012 R2. You can read more details about the affected versions in the Microsoft Security Bulletin.
The vulnerability is particularly severe because an attacker only needs to send an HTTP request with the right header to exploit it. We recommend applying the update as soon as possible.