Junglewise Threat Intelligence

CVE-1999-1128: Microsoft Internet Explorer arbitrary command execution via .isp file

CVE-1999-1128 · Severity: medium · CVSS 5.1 · Published 1997-03-01

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 3.01 on Windows 95 contains a flaw that allows malicious websites to run commands on a visitor's computer. By tricking a user into visiting a specially crafted site, an attacker could automatically download and run a configuration file that executes unauthorized programs. This could lead to the theft of personal data or the installation of harmful software without the user's knowledge or consent.

Technical details

A remote code execution vulnerability exists in Microsoft Internet Explorer 3.01 running on Windows 95. The browser fails to properly handle Internet Service Provider (.isp) files, which are used for automated internet connection setup. When a user visits a malicious website, the browser may automatically download and execute these files without a security prompt or user interaction. An attacker can leverage this behavior to execute arbitrary system commands on the victim's machine. The attack is delivered via the network and requires the victim to navigate to a malicious URL.

Affected products

  • Microsoft Internet Explorer 3.01

Timeline

  • 1997-03-01: disclosed: Initial publication date in NVD

References

Related threats