CVE-1999-1537
CVSS 2.0 Score 5 of 10 (medium)
Details
Published Jul 7, 1999
Updated: Nov 20, 2024
Summary
CVE-1999-1537 is a vulnerability affecting Microsoft IIS 3.x and 4.x servers. The issue stems from a failure to distinguish between encrypted and non-encrypted pages, leading to resource exhaustion and a denial of service. SSL requests to HTTPS ports for regular files, which should not be encrypted, will trigger IIS to perform additional work to send these files over SSL, ultimately causing the server to become overwhelmed and unresponsive.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft