Vulnerability record · CVE-1999-0449 · published 26 January 1999
CVE-1999-0449: IIS 4 ExAir sample site scripts allow remote CPU exhaustion DoS
Microsoft · Internet Information Server
The ExAir sample site shipped with IIS 4 exposes advsearch.asp, query.asp and search.asp, which can be requested directly to drive heavy CPU consumption. Because the scripts are reachable without authentication, a remote attacker can repeatedly hit them and degrade or stall the web server. The record is old and thin: no affected version range beyond IIS 4 and no fix detail are given.
Description
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
medium priorityRemote unauthenticated availability impact is real, but the flaw is confined to an obsolete IIS 4 sample site with no confirmed exploitation and no patch detail in the record.
What it is
The ExAir sample site shipped with IIS 4 exposes advsearch.asp, query.asp and search.asp, which can be requested directly to drive heavy CPU consumption. Because the scripts are reachable without authentication, a remote attacker can repeatedly hit them and degrade or stall the web server. The record is old and thin: no affected version range beyond IIS 4 and no fix detail are given.
Impact
An attacker can consume server CPU and cause a denial of service, making the IIS host unresponsive to legitimate requests. No data confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reachable over the network via HTTP requests to the ExAir sample site scripts; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so confirmed in-the-wild exploitation is not established. EPSS is high (0.49253, 98.8th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Remove or disable the ExAir sample site and its advsearch.asp, query.asp and search.asp scripts from IIS 4.
- Upgrade to a supported IIS release, since IIS 4 is long out of support and no patch is identified in this record.
- Restrict network access to the sample site or the affected scripts at the firewall or IIS level.
- Apply request rate limiting or connection throttling to blunt repeated CPU-heavy script requests.
Detection
- Monitor IIS logs for repeated requests to /ExAir/advsearch.asp, /ExAir/query.asp and /ExAir/search.asp from single sources.
- Alert on sustained high CPU on IIS hosts correlated with spikes in requests to those script paths.
- Baseline normal request rates to the sample site and flag deviations or high-volume single-IP patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-1999-0449 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-1999-0449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.