← Vulnerability feed

Vulnerability record · CVE-1999-0449 · published 26 January 1999

CVE-1999-0449: IIS 4 ExAir sample site scripts allow remote CPU exhaustion DoS

Microsoft · Internet Information Server

The ExAir sample site shipped with IIS 4 exposes advsearch.asp, query.asp and search.asp, which can be requested directly to drive heavy CPU consumption. Because the scripts are reachable without authentication, a remote attacker can repeatedly hit them and degrade or stall the web server. The record is old and thin: no affected version range beyond IIS 4 and no fix detail are given.

7.8 CVSS 2.0 High EPSS 49% · top 1.2%
7.8CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityRemote unauthenticated availability impact is real, but the flaw is confined to an obsolete IIS 4 sample site with no confirmed exploitation and no patch detail in the record.

What it is

The ExAir sample site shipped with IIS 4 exposes advsearch.asp, query.asp and search.asp, which can be requested directly to drive heavy CPU consumption. Because the scripts are reachable without authentication, a remote attacker can repeatedly hit them and degrade or stall the web server. The record is old and thin: no affected version range beyond IIS 4 and no fix detail are given.

Impact

An attacker can consume server CPU and cause a denial of service, making the IIS host unresponsive to legitimate requests. No data confidentiality or integrity impact is described; the effect is availability only.

Attack surface

Reachable over the network via HTTP requests to the ExAir sample site scripts; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, so confirmed in-the-wild exploitation is not established. EPSS is high (0.49253, 98.8th percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Remove or disable the ExAir sample site and its advsearch.asp, query.asp and search.asp scripts from IIS 4.
  • Upgrade to a supported IIS release, since IIS 4 is long out of support and no patch is identified in this record.
  • Restrict network access to the sample site or the affected scripts at the firewall or IIS level.
  • Apply request rate limiting or connection throttling to blunt repeated CPU-heavy script requests.

Detection

  • Monitor IIS logs for repeated requests to /ExAir/advsearch.asp, /ExAir/query.asp and /ExAir/search.asp from single sources.
  • Alert on sustained high CPU on IIS hosts correlated with spikes in requests to those script paths.
  • Baseline normal request rates to the sample site and flag deviations or high-volume single-IP patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-0449 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0075Microsoft IIS ASP code injection allows remote code executionCVE-2008-0075 is an unspecified code injection flaw in Microsoft Internet Information Services (IIS) 5.1 through 6.0 that is triggered by crafted inp…EPSS 57%analysed10.0CVE-2001-0500Microsoft IIS Index Server ISAPI idq.dll buffer overflowA buffer overflow in the ISAPI extension idq.dll, used by Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier, is triggered by a l…EPSS 97%analysed10.0CVE-1999-1011Microsoft MDAC RDS DataFactory unsafe methods allow remote command executionThe Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe metho…EPSS 77%analysed10.0CVE-1999-0874IIS 4.0 buffer overflow via malformed .HTR, .IDC, .STM requestsIIS 4.0 contains a memory buffer overflow reachable through malformed requests for files with .HTR, .IDC, or .STM extensions. The record describes th…EPSS 75%analysed10.0CVE-1999-0407Microsoft internet information server vulnerabilityBy default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to ident…EPSS 5.1%10.0CVE-1999-1376Microsoft internet information server vulnerabilityBuffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.EPSS 24%9.0CVE-2009-3023Microsoft IIS FTP Service buffer overflow via crafted NLST commandThe FTP Service in Microsoft IIS 5.0 through 6.0 contains a classic buffer overflow (CWE-120) triggered by a crafted NLST command using wildcards, ca…EPSS 91%analysed8.5CVE-2010-1256Microsoft internet information server code injection vulnerabilityUnspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated use…EPSS 28%

Source: NIST National Vulnerability Database (record CVE-1999-0449), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.