CVE-1999-0777: High severity Microsoft Commercial Internet System vulnerability
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Internet Information Servicesfrom your environment.Disable or uninstall the IIS FTP service/component until a security fix is available.
- Remove
Remove
Microsoft Commercial Internet Systemfrom your environment.Disable or uninstall the FTP service/component provided by Microsoft Commercial Internet System until a security fix is available.
- Compensating control
Restrict network access to FTP services (IIS and Microsoft Commercial Internet System) to trusted IP addresses using firewall rules or ACLs, or block FTP ports at the network edge until a fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0777?
CVE-1999-0777 is considered a critical vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-1999-0777?
To fix CVE-1999-0777, update your IIS FTP server to the latest security patch released by Microsoft.
What versions of IIS are affected by CVE-1999-0777?
CVE-1999-0777 affects Microsoft Internet Information Server version 4.0 and Microsoft Commercial Internet System version 2.5.
What are the consequences of exploiting CVE-1999-0777?
Exploiting CVE-1999-0777 can allow remote attackers to read or delete files on the FTP server, bypassing access controls.
Can CVE-1999-0777 be mitigated?
Mitigating CVE-1999-0777 involves applying security patches and implementing stricter file permissions on the FTP server.