First published: Fri Feb 19 1999(Updated: )
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =3.0 | |
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0412 is considered a critical vulnerability due to the potential for an attacker to execute commands as the SYSTEM user.
To mitigate CVE-1999-0412, it is recommended to upgrade to a newer version of Microsoft Internet Information Server that is not affected by this vulnerability.
CVE-1999-0412 affects Microsoft Internet Information Server versions 2.0, 3.0, and 4.0.
CVE-1999-0412 enables attackers to execute arbitrary commands on the server with SYSTEM privileges.
Yes, CVE-1999-0412 specifically affects Microsoft Internet Information Server and other web servers that load ISAPI extensions.