A vulnerability has been identified in Microsoft Internet Information Services (IIS), which could be exploited by attackers to compromise a vulnerable system. This issue is caused due to the server handling files with multiple extensions separated by the ";" character e.g. "malicious.asp;.jpg" as ASP pages, which could allow attackers to execute arbitrary code on a vulnerable web server by uploading a malicious file bypassing file extension protections and restrictions.