First published: Mon Jul 19 1999(Updated: )
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Data Access Components | =1.5 | |
Microsoft Data Access Components | =2.0 | |
Microsoft Data Access Components | =2.1 | |
Microsoft Index Server | =2.0 | |
Microsoft Internet Information Services | =3.0 | |
Microsoft Internet Information Services | =4.0 | |
Microsoft Site Server Commerce | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1011 has a high severity due to its ability to allow remote execution of arbitrary commands.
To fix CVE-1999-1011, it is recommended to update Microsoft Data Access Components to a secure version and restrict access to the affected components.
CVE-1999-1011 affects Microsoft Internet Information Server versions 3.0 and 4.0, Microsoft Data Access Components versions 1.5, 2.0, and 2.1, and Microsoft Site Server 3.0.
CVE-1999-1011 is a remote command execution vulnerability that exploits unsafe methods in DataFactory component of RDS.
Yes, CVE-1999-1011 can be exploited remotely without authentication, making it particularly dangerous.