PT-1999-1702 · Microsoft · Iis 4.0+1

Published

1999-03-23

·

Updated

2016-10-18

·

CVE-1999-1397

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Index Server 2.0 on IIS 4.0
Description: The issue allows local and remote users to obtain the physical paths of directories that are being indexed, as the ContentIndexCatalogs subkey of the AllowedPaths registry key stores this information with permissions that are not restrictive enough.
Recommendations: For Index Server 2.0 on IIS 4.0, consider restricting access to the AllowedPaths registry key to prevent unauthorized users from obtaining physical path information. As a temporary workaround, restrict access to the ContentIndexCatalogs subkey to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1397

Affected Products

Iis 4.0
Index Server 2.0