Description
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
References (3)
Core 3
Core References
Third Party Advisory mailing-list
x_refsource_ntbugtraq
http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00277.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/190
Third Party Advisory mailing-list
x_refsource_ntbugtraq
http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00276.html
Scores
EPSS
0.1127
EPSS Percentile
95.5%
Details
Status
published
Products (2)
microsoft/internet_information_server
4.0 sp4
microsoft/visual_interdev
6.0
Published
Dec 31, 1999
Tracked Since
Feb 18, 2026