Junglewise Threat Intelligence

CVE-1999-0280: Microsoft Internet Explorer remote command execution via .lnk and .url files

CVE-1999-0280 · Severity: high · CVSS 7.5 · Published 1997-04-01

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Internet Explorer allows attackers to execute unauthorized commands on a user's computer. This occurs when the web browser processes specially crafted shortcut files (.lnk or .url). An attacker could use this to gain control over a victim's system or access sensitive local data if the user visits a malicious website.

Technical details

A remote command execution vulnerability exists in Microsoft Internet Explorer 3.0 and 3.0.1. The flaw is rooted in how the browser handles Windows shortcut files (.lnk) and Uniform Resource Locator (.url) files. By enticing a user to download or interact with these files via a malicious webpage, an unauthenticated remote attacker can execute arbitrary commands on the target host. This bypasses security zones or restrictions intended to prevent local code execution from web content.

Affected products

  • Microsoft Internet Explorer 3.0, 3.0.1

Timeline

  • 1997-04-01: advisory: NVD published date

References

Related threats