First published: Tue Feb 09 1999(Updated: )
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Server | =4.0 | |
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0407 is considered a high severity vulnerability due to its potential to facilitate brute force password attacks.
To fix CVE-1999-0407, it is recommended to disable the /IISADMPWD virtual directory in IIS 4.0.
The risks associated with CVE-1999-0407 include unauthorized access attempts and the exposure of valid user accounts.
CVE-1999-0407 affects Microsoft Internet Information Server version 4.0.
Yes, CVE-1999-0407 can be exploited remotely, making it crucial to apply necessary security measures.