Junglewise Threat Intelligence

CVE-1999-1446: Microsoft Internet Explorer history deletion failure in DAT files

CVE-1999-1446 · Severity: low · CVSS 2.1 · Published 1997-08-05

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 3 fails to properly delete a user's browsing history when the "Clear History" option is selected. This results in a permanent record of visited websites and downloaded content being stored in hidden system files. An unauthorized person with physical or local access to the computer could recover this sensitive information, potentially leading to a loss of privacy or exposure of confidential activities.

Technical details

Internet Explorer 3 maintains persistent records of user activity in DAT files (such as MM2048.DAT and MM256.DAT) located within the 'Temporary Internet Files' and 'History' directories. A flaw exists where the 'Clear History' function in the browser UI fails to purge these underlying binary files. Furthermore, the Windows Explorer shell uses a 'tailored display' (shell extension) to hide these files from standard directory listings, creating a false sense of privacy. An attacker with local access can bypass the shell restrictions using a command-line interface or binary editor to extract a byte-by-byte record of all URLs visited, search queries made, and files uploaded or downloaded.

Affected products

  • Microsoft Internet Explorer 3.0

Timeline

  • 1997-08-05: disclosed: Initial public discussion on NTBUGTRAQ mailing list.
  • 1997-08-05: advisory: NVD publication date.

References

Related threats