CVE-1999-0561: Critical severity Microsoft Internet Information Services vulnerability
IIS has the #exec function enabled for Server Side Include (SSI) files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the #exec function for Server Side Include (SSI) files in IIS configuration — ensure the SSI exec command is removed/disabled or the SSI feature is configured to disallow #exec.
Microsoft Internet Information Services (IIS) - Server Side Includes (SSI) #exec function for SSI = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0561?
CVE-1999-0561 is considered a critical vulnerability due to the risk of remote code execution.
How do I fix CVE-1999-0561?
To fix CVE-1999-0561, disable the #exec function in Server Side Includes on IIS servers.
What systems are affected by CVE-1999-0561?
CVE-1999-0561 affects Microsoft Internet Information Services (IIS) with Server Side Include functionality.
What risks are associated with CVE-1999-0561?
The risks associated with CVE-1999-0561 include unauthorized access and execution of malicious commands on the server.
Is CVE-1999-0561 still a concern today?
Although CVE-1999-0561 is an older vulnerability, it remains a concern for legacy systems still using vulnerable IIS versions.