CVE-1999-1368: High severity Broadcom Inoculateit vulnerability

Published May 12, 1999
·
Updated

AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.

Affected Software

1 affected component
Broadcom Inoculateit=4.53

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the MS Exchange Server AV Option in InoculateIT until the vendor provides a fix, to avoid relying on scanning that only covers the Inbox folder tree.

    InoculateIT AV Option for MS Exchange Server = disabled
  2. Compensating control

    Restrict, audit, or prohibit Exchange mailbox rules that move incoming messages out of users' primary Inbox (or into other mailboxes) so messages remain in the Inbox where InoculateIT's Exchange option performs scanning.

  3. Operational

    Perform supplemental scanning of mailbox stores and folders outside the Inbox (for example, run manual scans or use an alternative scanning mechanism) to detect malware that may be missed by the InoculateIT Exchange option.

  4. Operational

    Contact InoculateIT vendor/support to confirm affected versions, request a patch or remediation, and monitor vendor advisories for a fix.

Event History

May 12, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1368?

CVE-1999-1368 is considered a moderate severity vulnerability due to the risk of undetected virus transmission in certain mailbox configurations.

2

How do I fix CVE-1999-1368?

To mitigate CVE-1999-1368, ensure that all user rules are configured to keep messages in the Inbox and regularly scan all mailboxes for viruses.

3

What systems are affected by CVE-1999-1368?

CVE-1999-1368 affects InoculateIT version 4.53 for Microsoft Exchange Server.

4

How does CVE-1999-1368 affect virus detection?

CVE-1999-1368 may allow viruses to escape detection if users' rules move infected messages out of the Inbox folder.

5

Is there a workaround for CVE-1999-1368?

A possible workaround for CVE-1999-1368 is to perform regular manual scans of other mailbox folders outside of the automated settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203