CVE-1999-1235: Medium severity Microsoft Internet Explorer vulnerability
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not use FTP URLs that include username and password in Internet Explorer; avoid embedding credentials in links or bookmarks.
- Compensating control
Restrict access to users' profile directories (including index.dat) via filesystem permissions or group policy so local users cannot read other users' URL history.
- Compensating control
Mitigate shoulder-surfing risk: ensure privacy when using Internet Explorer (prevent others from observing the screen or status bar when hovering links) and train users not to reveal credentials.
- Operational
Clear the browser URL history and remove index.dat files in affected user profiles to delete stored FTP usernames and passwords.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1235?
CVE-1999-1235 is considered to have a high severity due to the potential for exposed sensitive credentials.
How do I fix CVE-1999-1235?
To fix CVE-1999-1235, users should upgrade to a newer version of Internet Explorer that does not exhibit this vulnerability.
Who is affected by CVE-1999-1235?
CVE-1999-1235 affects users of Internet Explorer 5.0, particularly those using FTP services.
What are the risks associated with CVE-1999-1235?
The risks of CVE-1999-1235 include unauthorized access to FTP credentials by local users or physical onlookers.
Is there a permanent solution for CVE-1999-1235?
The permanent solution for CVE-1999-1235 is to upgrade to a secure, updated web browser version.