CVE-1999-1526: Medium severity Macromedia Shockwave Flash plugin vulnerability
Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Macromedia Shockwave Flash (Shockwave 7)from your environment.Uninstall Macromedia Shockwave Flash / Shockwave 7 from systems where it is not required.
- Configuration
Disable the auto-update feature in Macromedia Shockwave 7 to prevent transmission of user passwords and hard disk information to Macromedia.
Macromedia Shockwave 7 auto-update = disabled - Compensating control
Block or restrict outbound network access from affected hosts to Macromedia update servers (or unknown update endpoints) at the network perimeter or host firewall to prevent further data transmission.
- Operational
Assume exposed credentials may have been transmitted; rotate any passwords or credentials that may have been sent via the auto-update mechanism.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1526?
CVE-1999-1526 is considered a high-severity vulnerability due to the exposure of sensitive user information.
How does CVE-1999-1526 affect users?
CVE-1999-1526 affects users by transmitting their passwords and hard disk information to Macromedia without consent.
How do I fix CVE-1999-1526?
To fix CVE-1999-1526, users should uninstall the affected version of the Macromedia Shockwave Flash plugin, specifically version 7.0.
Which versions are affected by CVE-1999-1526?
CVE-1999-1526 specifically affects version 7.0 of the Macromedia Shockwave Flash plugin.
Is CVE-1999-1526 still a concern today?
While CVE-1999-1526 is an older vulnerability, it highlights the importance of auditing legacy software for security issues.