CVE-1999-1110

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Nov 14, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-1110 is a vulnerability affecting the Windows Media Player ActiveX object in Internet Explorer 5.0. When a non-existent file is attempted to be accessed, the player returns a specific error code. Malicious websites can exploit this issue to determine the existence of files on the client's system. This information disclosure vulnerability poses a potential risk to users browsing untrusted websites. The error code leakage occurs due to insufficient input validation, leading to unintended file status disclosures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Internet Explorer

Affected Vendors

  • Microsoft