CVE-1999-1538
CVSS Score Not Available
50.26%
MEDIUM RiskEPSS (98th percentile)
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
Published: 1/14/1999
Modified: 4/3/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
50.26%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 50.26% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.