CVE-1999-0490: High severity Microsoft Internet Explorer vulnerability
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Internet Explorer 5.0from your environment.Uninstall Internet Explorer 5.0 or remove/replace the affected MSHTML.DLL on affected systems if feasible.
- Configuration
Disable automatic loading of images (IMG SRC) in Internet Explorer to prevent information disclosure via IMG SRC tags.
MSHTML.DLL (Internet Explorer 5.0) automatic image loading (IMG SRC) = disabled - Compensating control
Block or filter external image requests and untrusted web content at the network boundary (proxy, firewall, or web filter) to prevent exploitation via IMG SRC tags.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0490?
CVE-1999-0490 is categorized as a medium severity vulnerability due to the potential information disclosure.
How do I fix CVE-1999-0490?
To fix CVE-1999-0490, you should upgrade to a newer version of Internet Explorer that does not contain this vulnerability.
What versions of Internet Explorer are affected by CVE-1999-0490?
CVE-1999-0490 affects Internet Explorer 4.0 and 5.0.
Can CVE-1999-0490 be exploited remotely?
Yes, CVE-1999-0490 can be exploited by a remote attacker using an IMG SRC tag.
What type of information can be disclosed by CVE-1999-0490?
CVE-1999-0490 allows an attacker to learn information about a local user's files.