CVE-1999-0967: Buffer Overflow

Published Nov 1, 1997
·
Updated

Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.

Affected Software

3 affected components
Microsoft Internet Explorer=4.0
Microsoft Outlook Express
Microsoft Windows Explorer

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove microsoft/outlook-express from your environment.

    Uninstall Microsoft Outlook Express if it is not required in your environment to eliminate exposure to the vulnerable HTML library.

  2. Remove

    Remove microsoft/internet-explorer from your environment.

    Uninstall or disable Internet Explorer where possible and where doing so will not break required functionality, to remove the affected HTML rendering component.

  3. Configuration

    If supported in your environment, disable handling of the res: (local resource) URI scheme in Internet Explorer to prevent use of the vulnerable HTML library via res: references.

    Internet Explorer res: protocol handling = disabled
  4. Configuration

    If supported, disable handling of the res: (local resource) URI scheme within Outlook Express to prevent rendering of HTML that could trigger the buffer overflow.

    Microsoft Outlook Express res: protocol handling = disabled
  5. Configuration

    If possible, disable handling of the res: (local resource) URI scheme in Windows (File) Explorer so local resource references cannot be used to exploit the HTML library.

    Windows File Explorer res: protocol handling = disabled
  6. Compensating control

    Deploy network- and gateway-level filtering (web proxy, URL filter, email gateway, or WAF) to block or remove res: URI scheme references and to filter untrusted HTML content that could reference local resources.

  7. Operational

    Monitor Microsoft security advisories and apply any official patches, hotfixes, or vendor guidance for the HTML library and handling of the res: protocol as soon as they are released.

Event History

Nov 1, 1997
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0967?

CVE-1999-0967 is considered a high severity vulnerability due to the potential for remote code execution through a buffer overflow.

2

How do I fix CVE-1999-0967?

To fix CVE-1999-0967, you should apply the latest patches and updates available for Internet Explorer, Outlook Express, and Windows Explorer.

3

Which versions are affected by CVE-1999-0967?

CVE-1999-0967 affects Internet Explorer 4.0, and versions of Outlook Express and Windows Explorer that utilize the vulnerable HTML library.

4

What types of attacks can exploit CVE-1999-0967?

CVE-1999-0967 can be exploited through specially crafted HTML content that triggers a buffer overflow.

5

Is there a workaround for CVE-1999-0967?

Disabling the use of local resource protocols or avoiding untrusted HTML content can serve as a temporary workaround for CVE-1999-0967.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203