CVE-1999-1380
CVSS 2.0 Score 5.1 of 10 (medium)
Details
Published May 4, 1997
Updated: Nov 20, 2024
Summary
CVE-1999-1380 is a vulnerability affecting the Symantec Norton Utilities 2.0 for Windows 95. This issue permits remote attackers to execute arbitrary commands by marking the TUNEOCX.OCX ActiveX control as safe for scripting. Malicious web pages accessed through Internet Explorer 3.0 can exploit this vulnerability, leading to serious security consequences. The vulnerability arises due to insufficient validation of user-supplied input, allowing attackers to bypass security restrictions and run unauthorized commands on affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Symantec