A Token Kidnapping vulnerability affecting Windows client and server operating systems via IIS and SQL Server has gone unpatched since April 2008, when Microsoft first informed the users of the issue. And even after proof of concept code for the security flaw has become available in the wild, the Redmond giant posted just an update to their original advisory and informed users that a patch is in the making, but failed to offer any deadline for the availability of the fix.[AD... (read more) Read »