CVE-1999-0766: Critical severity Microsoft Java Virtual Machine vulnerability
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Java Virtual Machinefrom your environment.Uninstall the Microsoft Java Virtual Machine from affected systems and remove any browser integration (remove/disable the Java plugin in Internet Explorer).
- Remove
Remove
Oracle Java Virtual Machinefrom your environment.Uninstall the Oracle Java Virtual Machine from affected systems or disable its browser plugin to eliminate the vulnerable Java runtime.
- Configuration
Disable the Java VM / Java browser plugin in Internet Explorer (e.g., via Manage Add-ons or Internet Options) to prevent Java applets from running.
Internet Explorer Java plugin (MS JVM / Oracle JVM) = disabled - Compensating control
Block or restrict execution of Java applets through network or endpoint controls (proxy/WAF rules, URL filtering, or application whitelisting) to prevent untrusted Java content from reaching users until the vulnerable runtime is removed or patched.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0766?
CVE-1999-0766 is considered critical due to its ability to allow arbitrary command execution.
How does CVE-1999-0766 exploit the Microsoft Java Virtual Machine?
CVE-1999-0766 exploits the Microsoft Java Virtual Machine by allowing malicious Java applets to run outside of their restricted environment.
What versions are affected by CVE-1999-0766?
CVE-1999-0766 affects the Microsoft Java Virtual Machine and Internet Explorer version 6.0.2900.
How can I mitigate CVE-1999-0766?
Mitigation for CVE-1999-0766 includes disabling the Microsoft Java Virtual Machine or using an updated browser.
Is there a patch for CVE-1999-0766?
Microsoft has recommended updating to secure versions and applying relevant security patches to address CVE-1999-0766.