CVE-1999-0281: Medium severity Microsoft Internet Information Server vulnerability
Denial of service in IIS using long URLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Internet Information Servicesfrom your environment.If IIS is not required, uninstall or disable the Microsoft Internet Information Services role to eliminate exposure to the long-URL denial-of-service issue.
- Compensating control
Deploy edge filtering (WAF, reverse proxy, or firewall) to block or reject HTTP requests with excessively long request URLs and implement rate-limiting to mitigate denial-of-service attempts against IIS.
- Operational
Monitor IIS hosts for signs of DoS (high CPU, memory, request queue depth) and enable/request logging of request URIs to detect long-URL attacks; perform service/restart or failover procedures to recover affected systems and apply vendor fixes when they are published.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0281?
CVE-1999-0281 is classified as a denial of service vulnerability affecting IIS and Internet Information Services.
How does CVE-1999-0281 exploit system vulnerabilities?
CVE-1999-0281 exploits the system by sending excessively long URLs, causing the server to become unresponsive.
Which versions are affected by CVE-1999-0281?
CVE-1999-0281 affects Microsoft Internet Information Server 3.0 and Internet Information Services 2.0.
How do I remediate CVE-1999-0281?
To remediate CVE-1999-0281, upgrade to a version of IIS that is not susceptible to this vulnerability.
What are the potential impacts of CVE-1999-0281?
The potential impacts of CVE-1999-0281 include downtime and loss of availability for web services hosted on the affected systems.