CVE-1999-1011 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 77.1% (pctl 100)
Patch early
A public exploit exists.
Description
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 77.14% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1999-07-19 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | data access components |
| microsoft | index server |
| microsoft | internet information server |
| microsoft | site server |
Public exploits
References
- http://www.ciac.org/ciac/bulletins/j-054.shtml
- http://www.osvdb.org/272
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025
- https://www.securityfocus.com/bid/529
- http://www.ciac.org/ciac/bulletins/j-054.shtml
- http://www.osvdb.org/272
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025
- https://www.securityfocus.com/bid/529
→ the Explorer · watch your stack · NVD