CVE-1999-0487: Low severity Microsoft Internet Explorer vulnerability

Published May 1, 1999
·
Updated

The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.

Affected Software

2 affected components
Microsoft Internet Explorer=4.0
Microsoft Internet Explorer=5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove the affected component from your environment.

    Unregister or remove the DHTML Edit ActiveX control from affected systems if it is not required.

  2. Configuration

    Disable the DHTML Edit ActiveX control in Internet Explorer (for example via browser security settings or Group Policy) to prevent the control from being loaded.

    Internet Explorer (DHTML Edit ActiveX control) DHTML Edit ActiveX control loading = disabled
  3. Compensating control

    Apply compensating controls such as blocking or restricting Internet Explorer/ActiveX usage via network controls, application whitelisting, or browser hardening to reduce exposure until the control is removed or fixed.

  4. Operational

    Audit and inventory systems for the presence of the DHTML Edit ActiveX control, and investigate systems for signs of arbitrary file reads; remediate affected hosts (remove control, restore from known-good backups) as needed.

Event History

May 1, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0487?

CVE-1999-0487 is considered a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files from a victim's system.

2

How do I fix CVE-1999-0487?

To fix CVE-1999-0487, users should update their Internet Explorer to a version that is not affected or apply any available security patches from Microsoft.

3

Which versions of Internet Explorer are affected by CVE-1999-0487?

CVE-1999-0487 affects Internet Explorer versions 4.0 and 5.0.

4

Can CVE-1999-0487 allow for data theft?

Yes, CVE-1999-0487 can potentially be exploited to steal sensitive data from users by reading arbitrary files.

5

Is there a workaround for CVE-1999-0487?

A workaround for CVE-1999-0487 involves disabling ActiveX controls in Internet Explorer until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203