First published: Thu Jan 14 1999(Updated: )
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1538 is classified as a high severity vulnerability due to potential unauthorized access to sensitive server information.
To fix CVE-1999-1538, remove the ism.dll file from the /scripts/iisadmin directory after upgrading to IIS 4.
CVE-1999-1538 affects systems running Microsoft Internet Information Server 4.0 that were upgraded from IIS 2 or 3.
An attacker exploiting CVE-1999-1538 can gain access to sensitive server information, including the Administrator's password.
While CVE-1999-1538 is an older vulnerability, it remains relevant for legacy systems that have not been updated or correctly configured.