CVE-1999-0487

CVSS 2.0 Score 2.6 of 10 (low)

Details

Published May 1, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0487 is a vulnerability affecting the DHTML Edit ActiveX control in early versions of Internet Explorer. An attacker can exploit this weakness to read arbitrary files on the targeted system. This issue represents a significant risk as it allows unauthorized access to sensitive data, potentially leading to privacy breaches or data theft. The vulnerability exists due to inadequate input validation and access control checks within the control. To mitigate this risk, it is recommended that users upgrade to the latest version of Internet Explorer or disable the DHTML Edit ActiveX control until a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Internet Explorer

Affected Vendors

  • Microsoft