CVE-1999-0229
CVSS 2.0 Score 5 of 10 (medium)
Details
Published May 12, 1999
Updated: Nov 20, 2024
Summary
CVE-1999-0229 is a denied-of-service vulnerability affecting Microsoft IIS (Internet Information Services) servers running on Windows NT. Malicious actors can exploit this issue by sending specially crafted HTTP requests to the targeted server, causing it to crash or become unresponsive. The vulnerability lies in the way IIS handles certain file requests with a ".." (dot-dot) sequence in the URL path. This can lead to a denial-of-service condition, making the server unavailable to legitimate users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft