This update resolves the "Session ID Cookie Marking" security vulnerability in Internet Information Services (IIS) 5.0 and is discussed in Microsoft Security Bulletin MS00-080. Download now to prevent a malicious user from connecting to the Web page you are viewing, assuming your identity, and placing orders or viewing your personal information.
When using .asp files, IIS cannot differentiate between secure and non-secure Session ID cookies (small data files that identify you to a Web site as you move around within that site). This update enables .asp files to mark Session ID cookies as "secure."




