CVE-1999-1451: Medium severity Microsoft Internet Information Server vulnerability
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Winmsdp.exe (Microsoft Internet Information Services 4.0)from your environment.Remove or delete the Winmsdp.exe sample file from the IIS 4.0 installation (webroot/sample directories) to prevent remote attackers from reading arbitrary files.
- Remove
Remove
Winmsdp.exe (Microsoft Site Server 3.0 Commerce)from your environment.Remove or delete the Winmsdp.exe sample file from the Site Server 3.0 installation to prevent remote attackers from reading arbitrary files.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1451?
CVE-1999-1451 is considered a critical vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-1999-1451?
To fix CVE-1999-1451, it is recommended to apply the official security patches provided by Microsoft for IIS 4.0 and Site Server 3.0.
What types of attacks can exploit CVE-1999-1451?
CVE-1999-1451 can be exploited by remote attackers to read arbitrary files on the server.
Which software versions are affected by CVE-1999-1451?
CVE-1999-1451 affects Microsoft Internet Information Server version 4.0 and Microsoft Site Server version 3.0.
Is there a workaround for CVE-1999-1451?
A potential workaround for CVE-1999-1451 is to disable the Winmsdp.exe sample file if it is not in use.