CVE-1999-1087: High severity Microsoft Internet Explorer vulnerability
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or normalize requests that use 32-bit (dotless) IP addresses at network perimeter devices (firewall, proxy, WAF) or on corporate web gateways so clients cannot reach web servers via dotless-IP URLs.
- Compensating control
Reduce trust for the Internet Explorer Local Intranet Zone: remove unnecessary sites from the zone, tighten zone privileges, and disable any automatic assignment of sites to the Local Intranet Zone where policy/tools allow, to limit what an incorrectly classified site can do.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1087?
CVE-1999-1087 is considered to have a moderate severity level due to its potential for unauthorized access and activities.
How do I fix CVE-1999-1087?
To fix CVE-1999-1087, upgrade your Internet Explorer to a version that does not allow dotless IP handling.
What software is affected by CVE-1999-1087?
CVE-1999-1087 affects Internet Explorer versions 4.0, 4.0.1, and 4.0.1 SP1.
What impact does CVE-1999-1087 have on security?
CVE-1999-1087 may lead to security vulnerabilities where malicious websites can exploit lax security zone settings.
Is CVE-1999-1087 still a concern for current systems?
CVE-1999-1087 is mainly a concern for legacy systems still running outdated versions of Internet Explorer.