CVE-1999-1526: Medium severity Macromedia Shockwave Flash plugin vulnerability

Published Mar 11, 1999
·
Updated

Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.

Affected Software

1 affected component
Macromedia Shockwave Flash plugin=7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Macromedia Shockwave Flash (Shockwave 7) from your environment.

    Uninstall Macromedia Shockwave Flash / Shockwave 7 from systems where it is not required.

  2. Configuration

    Disable the auto-update feature in Macromedia Shockwave 7 to prevent transmission of user passwords and hard disk information to Macromedia.

    Macromedia Shockwave 7 auto-update = disabled
  3. Compensating control

    Block or restrict outbound network access from affected hosts to Macromedia update servers (or unknown update endpoints) at the network perimeter or host firewall to prevent further data transmission.

  4. Operational

    Assume exposed credentials may have been transmitted; rotate any passwords or credentials that may have been sent via the auto-update mechanism.

Event History

Mar 11, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1526?

CVE-1999-1526 is considered a high-severity vulnerability due to the exposure of sensitive user information.

2

How does CVE-1999-1526 affect users?

CVE-1999-1526 affects users by transmitting their passwords and hard disk information to Macromedia without consent.

3

How do I fix CVE-1999-1526?

To fix CVE-1999-1526, users should uninstall the affected version of the Macromedia Shockwave Flash plugin, specifically version 7.0.

4

Which versions are affected by CVE-1999-1526?

CVE-1999-1526 specifically affects version 7.0 of the Macromedia Shockwave Flash plugin.

5

Is CVE-1999-1526 still a concern today?

While CVE-1999-1526 is an older vulnerability, it highlights the importance of auditing legacy software for security issues.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203