CVE-1999-1246
UnknownEPSS 9.21%
Last modified
CVE-1999-1246 is a vulnerability of currently unknown severity. Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.. EPSS estimates a 9.21% chance of exploitation in the next 30 days.
Description
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Site Server | 3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-1246?
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
How severe is CVE-1999-1246?
Severity scoring for CVE-1999-1246 is pending analysis. The EPSS model estimates a 9.21% probability of exploitation in the next 30 days.
How do I fix CVE-1999-1246?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 1999
- CVE-1999-1235Internet Explorer 5.0 records the username and password for …
- CVE-1999-1236Internet Anywhere Mail Server 2.3.1 stores passwords in plai…
- CVE-1999-1237Multiple buffer overflows in smbvalid/smbval SMB authenticat…
- CVE-1999-1241Internet Explorer, with a security setting below Medium, all…
- CVE-1999-1244IPFilter 3.2.3 through 3.2.10 allows local users to modify a…
- CVE-1999-1245vacm ucd-snmp SNMP server, version 3.52, does not properly d…
- CVE-1999-1247Vulnerability in HP Camera component of HP DCE/9000 in HP-UX…
- CVE-1999-1254Windows 95, 98, and NT 4.0 allow remote attackers to cause a…
- CVE-1999-1255Hyperseek allows remote attackers to modify the hyperseek co…
- CVE-1999-1256Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edi…
- CVE-1999-1259Microsoft Office 98, Macintosh Edition, does not properly in…
- CVE-1999-1260mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sens…
Are you affected by CVE-1999-1246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
