CVE-1999-0280: High severity Microsoft Internet Explorer vulnerability
Remote command execution in Microsoft Internet Explorer using .lnk and .url files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
microsoft/internet-explorerfrom your environment.Uninstall or remove Internet Explorer from systems where it is not required and replace with a supported browser to eliminate the vulnerable component.
- Configuration
Prevent Internet Explorer (and the browser-invoked Windows file associations) from automatically opening .lnk and .url shortcut files. Implement this via Group Policy or registry changes to block handling of .lnk and .url file types in the browser or disable automatic opening of downloaded shortcut files.
Internet Explorer open .lnk/.url shortcut files = disabled - Compensating control
Block or quarantine .lnk and .url files at the email gateway and web proxy; configure perimeter devices (mail filters, web proxies, WAFs) to prevent delivery or download of .lnk and .url files from untrusted sources.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0280?
CVE-1999-0280 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-1999-0280?
To fix CVE-1999-0280, ensure you are using a patched version of Microsoft Internet Explorer, ideally upgrading to a later version.
Which versions of Internet Explorer are affected by CVE-1999-0280?
CVE-1999-0280 affects Microsoft Internet Explorer versions 3.0 and 3.0.1.
What could happen if I am vulnerable to CVE-1999-0280?
If vulnerable to CVE-1999-0280, an attacker could potentially execute arbitrary commands on the affected system.
Is there a known exploit for CVE-1999-0280?
Yes, there are known exploits that take advantage of CVE-1999-0280 to execute commands remotely.