CVE-1999-1537

Internet Information Server 3.x-4.x - Denial of Service via SSL Requests to HTTPS Port

Title source: llm
STIX 2.1

Description

IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=93138827329577&w=2
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/521
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2352

Scores

EPSS 0.0853
EPSS Percentile 94.5%

Details

Status published
Products (2)
microsoft/internet_information_server 3.0
microsoft/internet_information_server 4.0
Published Jul 07, 1999
Tracked Since Feb 18, 2026