CVE-1999-1035: Medium severity Microsoft Internet Information Server vulnerability
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Internet Information Servicesfrom your environment.Uninstall Microsoft Internet Information Services (IIS) if the service is not required on the host to eliminate exposure to the malformed-GET denial-of-service vulnerability.
- Compensating control
Restrict access to HTTP/S (e.g., ports 80 and 443) to trusted IP addresses at the network firewall or perimeter ACLs to prevent remote attackers from sending malformed GET requests.
- Compensating control
Deploy a web application firewall (WAF) or request-filtering device in front of IIS to detect and block malformed GET requests that may cause the server to hang.
- Operational
If the server hangs due to a malformed GET request, restart the IIS service or the affected host to restore availability.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1035?
CVE-1999-1035 is classified as a denial of service vulnerability that can disrupt the availability of affected systems.
How do I fix CVE-1999-1035?
To mitigate CVE-1999-1035, it is recommended to upgrade to a later version of Microsoft Internet Information Server that is not vulnerable.
Which versions of IIS are affected by CVE-1999-1035?
IIS versions 3.0 and 4.0 on x86 and Alpha architectures are affected by CVE-1999-1035.
What type of attack is associated with CVE-1999-1035?
CVE-1999-1035 is associated with an attack that involves sending a malformed GET request to the server.
Can CVE-1999-1035 be exploited remotely?
Yes, CVE-1999-1035 can be exploited remotely by attackers to cause a denial of service.