NT Versions Affected:

3.51, 4.0


Problem:

Anonymous users have same access rights as Domain Users.

Installing IIS on a PDC (typical) results in IUSR_<nodename> account becoming member of 'Domain Users'. This gives anonymous guests the access rights of 'Domain Users' group instead of 'Guests' group.


Verification:

http://www.microsoft.com/kb/articles/q147/6/91.htm