peter bassill · operator
$ cve CVE-1999-0412 JSON

CVE-1999-0412 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 10.2% (pctl 96)

Patch early

A public exploit exists.

Description

In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS10.24% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published1999-02-19
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftinternet information server
microsoftinternet information services

Public exploits

SourceTitleDate
exploit-dbMicrosoft IIS 2.0/3.0/4.0 - ISAPI GetExtensionVersion()1999-03-08

References

→ the Explorer  ·  watch your stack  ·  NVD