PT-1999-1568 · Microsoft · Internet Explorer
Published
1999-12-31
·
Updated
2021-07-22
·
CVE-1999-1087
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer version 4
Description
The issue allows remote malicious web servers to conduct unauthorized activities by using URLs that contain a dotless IP address for their server. This occurs because Internet Explorer 4 treats a 32-bit number in a URL as the hostname instead of an IP address, causing it to apply Local Intranet Zone settings to the resulting web page.
Recommendations
For Internet Explorer version 4, consider avoiding the use of dotless IP addresses in URLs until a fix is available. As a temporary workaround, restrict access to potentially malicious web servers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer