IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.Referenceshttp://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246401http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txthttps://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-061