This cumulative patch from Microsoft includes the functionality of all security patches released for Microsoft IIS, (all versions). The patch covers ten new vulnerabilities, the most serious of which could enable code of an attacker’s choice to be run on a server.
See the links below to learn more, and to get the patch.
Customer Security Bulletin (CSB02-01): Cumulative Patch for Internet Information Services