PT-1999-1625 · Microsoft · Site Server
Published
1999-12-31
·
Updated
2017-10-10
·
CVE-1999-1246
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Site Server version 3.0
Description
The issue concerns the Direct Mailer feature, which stores user domain names and passwords in plaintext within the TMLBQueue network share. This share has default permissions that are insecure, allowing remote attackers to read the passwords and potentially gain privileges.
Recommendations
For Microsoft Site Server version 3.0, consider restricting access to the TMLBQueue network share to minimize the risk of exploitation, and change the default permissions to secure ones. Additionally, avoid using the Direct Mailer feature until a secure method of storing credentials is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Site Server