The "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise" security patch eliminates a newly discovered vulnerability that involves a buffer overrun in the Chunked Encoding data transfer mechanism in IIS 4.0 and 5.0 and could be used to overrun heap memory on the system, with the result of either causing the IIS service to fail or allowing code to be run on the server. The vulnerability lies in the ISAPI extension that implements HTR – an older, largely obsolete scripting technology. To ensure that servers are fully protected against past and current vulnerabilities, Microsoft strongly recommends installing the previous Microsoft IIS cumulative patch first.