CVE-1999-0917: Medium severity Microsoft Internet Explorer vulnerability
The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Internet Explorer Preloader ActiveX controlfrom your environment.Uninstall or unregister the Preloader ActiveX control from affected systems if it is not required.
- Configuration
Disable the Preloader ActiveX control in Internet Explorer (for example via Manage Add-ons or by unregistering the ActiveX control) to prevent it from being instantiated by web content.
Internet Explorer (Preloader ActiveX control) enabled = false - Compensating control
Mitigate exposure until the control is removed or disabled: restrict execution of ActiveX controls in Internet Explorer (use high security settings or whitelist-only sites), and block or filter access to sites known to host the vulnerable Preloader control using network controls (proxy, firewall, or web application firewall).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0917?
CVE-1999-0917 is classified as a moderate vulnerability.
How do I fix CVE-1999-0917?
To fix CVE-1999-0917, update your Internet Explorer to version 5.01 or later.
What does CVE-1999-0917 allow attackers to do?
CVE-1999-0917 allows remote attackers to read arbitrary files on the affected system.
Which versions of Internet Explorer are affected by CVE-1999-0917?
CVE-1999-0917 affects Internet Explorer versions 4.0 and 5.0.
Is there a workaround for CVE-1999-0917?
A potential workaround for CVE-1999-0917 is to disable the Preloader ActiveX control if not needed.