Skip to main content

CVE-1999-1538

CVSS Score Not Available
50.26%
MEDIUM RiskEPSS (98th percentile)

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

Published: 1/14/1999
Modified: 4/3/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

50.26%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 50.26% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.