CVE-1999-0489

CVSS 2.0 Score 10 of 10 (high)

Details

Published May 17, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0489 refers to a vulnerability in MSHTML.DLL, a component of Internet Explorer 5.0. This issue enables remote attackers to exploit the file upload intrinsic control through a maliciously crafted paste operation. This vulnerability, also known as "untrusted scripted paste," was previously described in Microsoft's Security Bulletin MS98-013. Attackers could manipulate users into pasting a file name into this control, allowing them to upload and execute malicious code on the victim's system. This vulnerability posed a significant risk to users browsing the web and could lead to various types of cyber attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows NT

Affected Vendors

  • Microsoft