CVE-1999-0229

CVSS 2.0 Score 5 of 10 (medium)

Details

Published May 12, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0229 is a denied-of-service vulnerability affecting Microsoft IIS (Internet Information Services) servers running on Windows NT. Malicious actors can exploit this issue by sending specially crafted HTTP requests to the targeted server, causing it to crash or become unresponsive. The vulnerability lies in the way IIS handles certain file requests with a ".." (dot-dot) sequence in the URL path. This can lead to a denial-of-service condition, making the server unavailable to legitimate users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share