CVE-1999-0766: Critical severity Microsoft Java Virtual Machine vulnerability

Published Oct 21, 1999
·
Updated

The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.

Affected Software

3 affected components
Microsoft Java Virtual Machine
Microsoft Internet Explorer=6.0.2900
Microsoft Internet Explorer=6.0.2900

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Microsoft Java Virtual Machine from your environment.

    Uninstall the Microsoft Java Virtual Machine from affected systems and remove any browser integration (remove/disable the Java plugin in Internet Explorer).

  2. Remove

    Remove Oracle Java Virtual Machine from your environment.

    Uninstall the Oracle Java Virtual Machine from affected systems or disable its browser plugin to eliminate the vulnerable Java runtime.

  3. Configuration

    Disable the Java VM / Java browser plugin in Internet Explorer (e.g., via Manage Add-ons or Internet Options) to prevent Java applets from running.

    Internet Explorer Java plugin (MS JVM / Oracle JVM) = disabled
  4. Compensating control

    Block or restrict execution of Java applets through network or endpoint controls (proxy/WAF rules, URL filtering, or application whitelisting) to prevent untrusted Java content from reaching users until the vulnerable runtime is removed or patched.

Event History

Oct 21, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0766?

CVE-1999-0766 is considered critical due to its ability to allow arbitrary command execution.

2

How does CVE-1999-0766 exploit the Microsoft Java Virtual Machine?

CVE-1999-0766 exploits the Microsoft Java Virtual Machine by allowing malicious Java applets to run outside of their restricted environment.

3

What versions are affected by CVE-1999-0766?

CVE-1999-0766 affects the Microsoft Java Virtual Machine and Internet Explorer version 6.0.2900.

4

How can I mitigate CVE-1999-0766?

Mitigation for CVE-1999-0766 includes disabling the Microsoft Java Virtual Machine or using an updated browser.

5

Is there a patch for CVE-1999-0766?

Microsoft has recommended updating to secure versions and applying relevant security patches to address CVE-1999-0766.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203