← Vulnerability feed

Vulnerability record · CVE-1999-1011 · published 19 July 1999

CVE-1999-1011: Microsoft MDAC RDS DataFactory unsafe methods allow remote command execution

Microsoft · Data Access Components

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe methods that permit remote command execution. Because the flaw is reachable over the network with no authentication, it is a full-compromise issue for any exposed IIS host running the affected component. The record is old and thin on technical detail, but the impact class is unambiguous.

10.0 CVSS 2.0 High EPSS 77% · top 0.5% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated remote command execution with a CVSS 2.0 base score of 10 and very high EPSS probability on internet-facing IIS hosts.

What it is

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe methods that permit remote command execution. Because the flaw is reachable over the network with no authentication, it is a full-compromise issue for any exposed IIS host running the affected component. The record is old and thin on technical detail, but the impact class is unambiguous.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the server, gaining full control of confidentiality, integrity and availability of the host.

Attack surface

Reached over the network via the RDS DataFactory interface exposed through IIS 3.x/4.x; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.7714 (99.5th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Apply the Microsoft security bulletins MS98-004 and MS99-025 fixes, or upgrade to a supported IIS/MDAC release.
  • Disable or remove the RDS DataFactory component and any unnecessary MDAC RDS handlers on IIS servers.
  • Block external access to RDS/DataFactory endpoints at the firewall or reverse proxy.
  • Retire or isolate IIS 3.x/4.x hosts, which are long past end of support.
  • Restrict the IIS service account's privileges to limit command execution impact.

Detection

  • Monitor IIS logs for requests to RDS/DataFactory handler paths, especially unusual or malformed method calls.
  • Alert on unexpected child processes spawned by the IIS or MDAC service account.
  • Review network traffic to RDS-related ports and endpoints for anomalous outbound connections from web servers.
  • Audit servers for the presence of the RDS DataFactory component and flag any still exposed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-1011 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0075Microsoft IIS ASP code injection allows remote code executionCVE-2008-0075 is an unspecified code injection flaw in Microsoft Internet Information Services (IIS) 5.1 through 6.0 that is triggered by crafted inp…EPSS 57%analysed10.0CVE-2003-0903Microsoft data access components memory buffer overflow vulnerabilityBuffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a mal…EPSS 37%10.0CVE-2002-1918Microsoft data access components vulnerabilityBuffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown …EPSS 16%10.0CVE-2001-0500Microsoft IIS Index Server ISAPI idq.dll buffer overflowA buffer overflow in the ISAPI extension idq.dll, used by Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier, is triggered by a l…EPSS 97%analysed10.0CVE-1999-0874IIS 4.0 buffer overflow via malformed .HTR, .IDC, .STM requestsIIS 4.0 contains a memory buffer overflow reachable through malformed requests for files with .HTR, .IDC, or .STM extensions. The record describes th…EPSS 75%analysed10.0CVE-1999-0407Microsoft internet information server vulnerabilityBy default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to ident…EPSS 5.1%10.0CVE-1999-1376Microsoft internet information server vulnerabilityBuffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.EPSS 24%9.8CVE-2012-1891Microsoft data access components memory buffer overflow vulnerabilityHeap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…EPSS 29%

Source: NIST National Vulnerability Database (record CVE-1999-1011), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.