CVE-1999-0412
UnknownEPSS 10.24%
Last modified
CVE-1999-0412 is a vulnerability of currently unknown severity. In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.. EPSS estimates a 10.24% chance of exploitation in the next 30 days.
Description
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Information Server | 3.0 |
| Microsoft | Internet Information Server | 4.0 |
| Microsoft | Internet Information Services | 2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-0412?
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
How severe is CVE-1999-0412?
Severity scoring for CVE-1999-0412 is pending analysis. The EPSS model estimates a 10.24% probability of exploitation in the next 30 days.
How do I fix CVE-1999-0412?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 1999
- CVE-1999-0406Digital Unix Networker program nsralist has a buffer overflo…
- CVE-1999-0407By default, IIS 4.0 has a virtual directory /IISADMPWD which…
- CVE-1999-0408Files created from interactive shell sessions in Cobalt RaQ …
- CVE-1999-0409Buffer overflow in gnuplot in Linux version 3.5 allows local…
- CVE-1999-0410The cancel command in Solaris 2.6 (i386) has a buffer overfl…
- CVE-1999-0411Several startup scripts in SCO OpenServer Enterprise System …
- CVE-1999-0413A buffer overflow in the SGI X server allows local users to …
- CVE-1999-0414In Linux before version 2.0.36, remote attackers can spoof a…
- CVE-1999-0415The HTTP server in Cisco 7xx series routers 3.2 through 4.2 …
- CVE-1999-0416Vulnerability in Cisco 7xx series routers allows a remote at…
- CVE-1999-041764 bit Solaris 7 procfs allows local users to perform a deni…
- CVE-1999-0418Denial of service in SMTP applications such as Sendmail, whe…
Are you affected by CVE-1999-0412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
