PT-1999-1797 · Microsoft · Internet Explorer
Published
1999-09-10
·
Updated
2021-07-22
·
CVE-1999-1575
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Internet Explorer versions 4.01 through 5.0
Description:
The issue allows remote attackers to create and modify files and execute arbitrary commands due to certain ActiveX controls being marked as "Safe for Scripting". The affected ActiveX controls include Image Edit, Image Annotation, Image Scan, Thumbnail Image, Image Admin, HHOpen, Registration Wizard, and IE Active Setup.
Recommendations:
For Internet Explorer versions 4.01 through 5.0, consider disabling the affected ActiveX controls to minimize the risk of exploitation.
Restrict access to the
imgedit.ocx, imgscan.ocx, imgthumb.ocx, imgadmin.ocx, hhopen.ocx, and regwizc.dll modules to prevent remote attackers from creating and modifying files and executing arbitrary commands.
Avoid using the setupctl.dll in the affected IE Active Setup until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer