CVE-1999-0386: Medium severity Microsoft Personal Web Server vulnerability
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Personal Web Serverfrom your environment.Uninstall Microsoft Personal Web Server from affected systems if the component is not required.
- Remove
Remove
Microsoft Office FrontPagefrom your environment.Uninstall Microsoft Office FrontPage (FrontPage Personal Web Server components) from affected systems if the component is not required.
- Compensating control
If the components cannot be removed immediately, restrict access to the affected web services to trusted IP ranges only (via firewall, ACLs, or network isolation) and block public/untrusted network access to the servers hosting these services.
- Operational
Review server logs and access records for signs of unauthorized file reads or data exposure and investigate any suspicious activity; preserve logs for incident response.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0386?
CVE-1999-0386 has a high severity rating due to the ability of a remote attacker to read sensitive files on the server.
How do I fix CVE-1999-0386?
To mitigate CVE-1999-0386, disable the Microsoft Personal Web Server and use secure configurations in your web applications.
Which products are affected by CVE-1999-0386?
CVE-1999-0386 affects Microsoft Personal Web Server 4.0 and Microsoft Office FrontPage.
Can CVE-1999-0386 allow unauthorized file access?
Yes, CVE-1999-0386 allows remote attackers to gain unauthorized access to files on the server.
Is there a patch available for CVE-1999-0386?
There is no patch specifically mentioned for CVE-1999-0386, so users are advised to implement workarounds and security best practices.