← Vulnerability feed

Vulnerability record · CVE-1999-0278 · published 1 June 1998

CVE-1999-0278: IIS ASP source code disclosure via ::$DATA URL suffix

Microsoft · Internet Information Server

Microsoft IIS fails to properly handle NTFS alternate data stream syntax in URLs, allowing remote attackers to retrieve the source code of ASP files by appending "::$DATA" to the request. Because ASP source often contains credentials, connection strings and business logic, disclosure of the raw file is a meaningful information leak rather than a mere nuisance.

5.0 CVSS 2.0 Medium EPSS 65% · top 0.8%
5.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote source code disclosure with a very high EPSS percentile, though the affected platform is legacy and the CVSS base score is only medium.

What it is

Microsoft IIS fails to properly handle NTFS alternate data stream syntax in URLs, allowing remote attackers to retrieve the source code of ASP files by appending "::$DATA" to the request. Because ASP source often contains credentials, connection strings and business logic, disclosure of the raw file is a meaningful information leak rather than a mere nuisance.

Impact

An unauthenticated attacker gains read access to the source of server-side ASP scripts, exposing embedded secrets, database credentials and application logic that can be reused for further attacks.

Attack surface

Reachable over the network via a crafted HTTP request to the web server; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high (0.648, 99.2nd percentile), suggesting substantial observed or expected exploitation activity.

What to do

  • Apply the vendor fix referenced in Microsoft security bulletin MS98-003 and upgrade IIS to a supported, patched release.
  • Retire or isolate any IIS/Windows NT host still running this vintage of software, since it is far past end of support.
  • Block or normalize requests containing NTFS alternate data stream syntax such as "::$DATA" at the web server or WAF layer.
  • Remove sensitive values from ASP source where possible and store secrets outside the web root.
  • Restrict network exposure of legacy IIS servers to trusted clients only.

Detection

  • Search web server access logs for requests containing "::$DATA" or other alternate data stream markers.
  • Alert on HTTP responses returning ASP file contents with source markers such as "<%" instead of rendered HTML.
  • Monitor for bulk or sequential requests to .asp paths from a single source, which may indicate source harvesting.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-0278 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed7.8CVE-2002-0367Windows NT/2000 smss.exe debugging subsystem privilege escalationThe smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a lo…KEVEPSS 4.9%analysed10.0CVE-2008-0075Microsoft IIS ASP code injection allows remote code executionCVE-2008-0075 is an unspecified code injection flaw in Microsoft Internet Information Services (IIS) 5.1 through 6.0 that is triggered by crafted inp…EPSS 57%analysed10.0CVE-2005-0050Windows License Logging Service buffer overflow via unvalidated message lengthThe License Logging service in Windows NT Server, Windows 2000 Server and Windows Server 2003 fails to validate the length of messages, producing an …EPSS 47%analysed10.0CVE-2004-0568Microsoft windows 2000 vulnerabilityHyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that…EPSS 35%10.0CVE-2004-0571Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via…EPSS 31%10.0CVE-2004-0900Microsoft windows nt vulnerabilityThe DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, wh…EPSS 26%10.0CVE-2004-0901Microsoft windows 2000 vulnerabilityMicrosoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote att…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-1999-0278), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.