CVE-1999-1376: Buffer Overflow
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft FrontPage Server Extensions (fpcount.exe)from your environment.Uninstall FrontPage Server Extensions from the IIS server or remove/rename fpcount.exe if the FrontPage functionality is not required.
- Configuration
Disable FrontPage Server Extensions (which provides fpcount.exe) in IIS so fpcount.exe cannot be invoked.
Microsoft Internet Information Services (FrontPage Server Extensions) FrontPage Server Extensions / fpcount.exe = disabled - Compensating control
Restrict network access to the IIS server and block requests that invoke FrontPage Server Extensions/fpcount.exe at the perimeter firewall or web application firewall until a vendor-provided fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1376?
CVE-1999-1376 has been classified with high severity due to its potential for remote code execution.
How do I fix CVE-1999-1376?
To remediate CVE-1999-1376, it is recommended to upgrade from IIS 4.0 with FrontPage Server Extensions to a more secure version of Internet Information Services.
What systems are affected by CVE-1999-1376?
CVE-1999-1376 affects Microsoft Internet Information Server 4.0 when it is used with FrontPage Server Extensions.
Can CVE-1999-1376 be exploited remotely?
Yes, CVE-1999-1376 can be exploited remotely by attackers to execute arbitrary commands on the affected system.
What should I do if I cannot patch for CVE-1999-1376?
If patching is not possible for CVE-1999-1376, consider implementing network security controls such as firewalls to restrict access to the vulnerable service.