First published: Fri Dec 31 1999(Updated: )
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =3.0 | |
Microsoft Internet Information Services | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1035 is classified as a denial of service vulnerability that can disrupt the availability of affected systems.
To mitigate CVE-1999-1035, it is recommended to upgrade to a later version of Microsoft Internet Information Server that is not vulnerable.
IIS versions 3.0 and 4.0 on x86 and Alpha architectures are affected by CVE-1999-1035.
CVE-1999-1035 is associated with an attack that involves sending a malformed GET request to the server.
Yes, CVE-1999-1035 can be exploited remotely by attackers to cause a denial of service.