Data Execution Prevention errors

Mark R

Diamond Member
Oct 9, 1999
8,513
16
81
One of our servers has suddenly started popping up 'Data execution prevention' warnings for 'IIS worker process'.

Nothing much shows up in the event logs except for several application errors in w3wp.exe (again with an abrupt onset recently). Web logs reveal nothing exciting and firewall logs don't reveal any obvious coordinated attack.

It runs 2k3 SP1 with IIS 6 serving a mixture of ASP, ASP.NET, SSL and non-SSL sites, together with a local SQL server. The box is itself hardware firewalled for non-essential ports, and runs Win2k3 firewall with rather aggressive settings. Nevertheless, ports 80 and 443 are fully exposed.

No deliberate configuration changes coincide with the flurry of errors.

Any ideas? Where can we go from here?