CVE-1999-1591: High severity microsoft visual interdev vulnerability
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Obtain and install the hotfixes released for Microsoft IIS 4.0 SP4 that address the authentication bypass. If hotfixes cannot be applied immediately, restrict or block connections from Microsoft Visual InterDev 6.0 clients to the IIS server (for example via firewall rules or network ACLs) until the server is patched.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1591?
CVE-1999-1591 is considered a critical vulnerability due to its ability to allow remote attackers to bypass authentication requirements.
How do I fix CVE-1999-1591?
To fix CVE-1999-1591, ensure that all relevant hotfixes for Microsoft Internet Information Services 4.0 SP4 are applied.
What software versions are affected by CVE-1999-1591?
CVE-1999-1591 affects Microsoft Internet Information Services 4.0 SP4 and Microsoft Visual Interdev 6.0 without certain hotfixes.
Can CVE-1999-1591 be exploited remotely?
Yes, CVE-1999-1591 can be exploited remotely, allowing unauthorized access to the IIS server.
What are the risks associated with CVE-1999-1591?
The risks associated with CVE-1999-1591 include unauthorized access to sensitive data and potential system compromise.