CVE-1999-1537: Medium severity Microsoft Internet Information Server vulnerability

Published Jul 7, 1999
·
Updated

IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.

Affected Software

2 affected components
Microsoft Internet Information Server=3.0
Microsoft Internet Information Server=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove HTTPS bindings or disable SSL for files/pages that do not require encryption so IIS does not perform extra work sending normally-unencrypted files over SSL.

    Microsoft Internet Information Services (IIS) 3.x and 4.x HTTPS/SSL binding = disable HTTPS for content that does not require encryption
  2. Compensating control

    Restrict or filter access to the HTTPS port (TCP 443) at the network perimeter (firewall, load balancer, or WAF) to trusted IPs and/or implement rate-limiting to mitigate resource-exhaustion attacks via SSL requests.

Event History

Jul 7, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1537?

CVE-1999-1537 is classified as a denial of service vulnerability due to the resource exhaustion it can cause.

2

How do I fix CVE-1999-1537?

To mitigate CVE-1999-1537, ensure that SSL is only applied to pages that require encryption and consider upgrading to a more secure version of IIS.

3

Which versions of IIS are affected by CVE-1999-1537?

CVE-1999-1537 affects Microsoft Internet Information Server versions 3.0 and 4.0.

4

What kind of attacks can CVE-1999-1537 facilitate?

CVE-1999-1537 can facilitate denial of service attacks via unsolicited SSL requests to unencrypted files.

5

Is there a workaround for CVE-1999-1537?

A possible workaround for CVE-1999-1537 is to restrict access to the HTTPS port for files that do not require SSL.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203