Those might not seem a big deal, but you've just provided quite a lot of hints about what the attack surface looks like. Most vulnerability scans will flag up "leakage" of data. IIS also does annoying things by default like "powered by IIS" type HTTP headers (it's not alone in that of course). You'll usually be warned to switch that off because you don't want to make attacks easier than they otherwise would be. Internal error form leakage is just another example.