PT-1999-1092 · Microsoft · Iis

Published

1999-02-09

·

Updated

2016-10-18

·

CVE-1999-0407

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IIS version 4.0
Description The issue concerns a virtual directory /IISADMPWD in IIS 4.0 that contains files which can be utilized as proxies for brute force password attacks or to identify valid users on the system.
Recommendations For IIS version 4.0, consider removing or restricting access to the virtual directory /IISADMPWD to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-0407

Affected Products

Iis