Allaire Security Bulletin (ASB00-24): Microsoft (MS00-060): Patch Available for IIS Cross-Site Scripting Vulnerabilities
Microsoft has released a patch that eliminates security vulnerabilities in Microsoft(r) Internet Information Server. The vulnerabilities could allow a malicious web site operator to misuse another web site as a means of attacking users. This is not an issue with ColdFusion Server, but it is an issue that can affect ColdFusion users, as described in the Issue section. Allaire recommends that customers follow the instructions posted on the Microsoft web site to address this issue.
Here?s more information on the topic:
Allaire Security Bulleting ASB00-24