CVE-1999-0700: Buffer Overflow
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Phone Dialer (dialer.exe)from your environment.Uninstall or remove Phone Dialer from affected Windows 2000/NT systems if the application is not required.
- Configuration
Disable or prevent execution of Phone Dialer (dialer.exe) until an official fix is available.
Microsoft Phone Dialer (dialer.exe) enabled = false - Compensating control
Restrict write/modify permissions on the dialer.ini file and its directory to trusted administrators only, or remove/validate dialer.ini entries from untrusted sources to prevent malformed entries from being processed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0700?
CVE-1999-0700 has a moderate severity rating due to its potential for a buffer overflow that can lead to system compromise.
How does CVE-1999-0700 affect users?
CVE-1999-0700 can allow an attacker to execute arbitrary code on a vulnerable system through a specially crafted dialer entry.
How do I fix CVE-1999-0700?
To fix CVE-1999-0700, users should apply the latest updates and patches from Microsoft to secure their affected systems.
Which versions of Microsoft software are affected by CVE-1999-0700?
CVE-1999-0700 affects multiple versions of Microsoft Windows NT and Windows 2000, particularly version 4.0 and its service packs.
Is CVE-1999-0700 still a relevant threat today?
While CVE-1999-0700 is an older vulnerability, systems still running affected versions remain at risk, making it relevant for legacy systems.