CVE-1999-1575
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 36%
from disclosure to weapon0 days
Published on NVDApr 21
1st PoCSep 27
exploitation probability
36%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/19528exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/19515exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/19521⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-037https://exchange.xforce.ibmcloud.com/vulnerabilities/7097http://www.kb.cert.org/vuls/id/23412http://www.kb.cert.org/vuls/id/24839http://www.kb.cert.org/vuls/id/26924http://www.kb.cert.org/vuls/id/41408http://www.kb.cert.org/vuls/id/9162http://www.securityfocus.com/archive/1/28719