CVE-1999-0487: Low severity Microsoft Internet Explorer vulnerability
The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove the affected component from your environment.
Unregister or remove the DHTML Edit ActiveX control from affected systems if it is not required.
- Configuration
Disable the DHTML Edit ActiveX control in Internet Explorer (for example via browser security settings or Group Policy) to prevent the control from being loaded.
Internet Explorer (DHTML Edit ActiveX control) DHTML Edit ActiveX control loading = disabled - Compensating control
Apply compensating controls such as blocking or restricting Internet Explorer/ActiveX usage via network controls, application whitelisting, or browser hardening to reduce exposure until the control is removed or fixed.
- Operational
Audit and inventory systems for the presence of the DHTML Edit ActiveX control, and investigate systems for signs of arbitrary file reads; remediate affected hosts (remove control, restore from known-good backups) as needed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0487?
CVE-1999-0487 is considered a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files from a victim's system.
How do I fix CVE-1999-0487?
To fix CVE-1999-0487, users should update their Internet Explorer to a version that is not affected or apply any available security patches from Microsoft.
Which versions of Internet Explorer are affected by CVE-1999-0487?
CVE-1999-0487 affects Internet Explorer versions 4.0 and 5.0.
Can CVE-1999-0487 allow for data theft?
Yes, CVE-1999-0487 can potentially be exploited to steal sensitive data from users by reading arbitrary files.
Is there a workaround for CVE-1999-0487?
A workaround for CVE-1999-0487 involves disabling ActiveX controls in Internet Explorer until a patch is applied.