Microsoft-IIS is used by 11.4% of all websites and version 6 is roughly around 1.3%. The vulnerability was exploited in wild of June or July and disclosed publically by March 27. Microsoft ends support for IIS 6.0 already on July 14, 2015, there is no patch for this vulnerability. Successful exploitation could result in denial of service attack or arbitrary code execution with regards to the client running the application. Windows server that shipped with newer versions of IIS are not affected by the vulnerability.”]

