Vulnerability record · CVE-1999-1011 · published 19 July 1999
CVE-1999-1011: Microsoft MDAC RDS DataFactory unsafe methods allow remote command execution
Microsoft · Data Access Components
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe methods that permit remote command execution. Because the flaw is reachable over the network with no authentication, it is a full-compromise issue for any exposed IIS host running the affected component. The record is old and thin on technical detail, but the impact class is unambiguous.
Description
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 2.0 base score of 10 and very high EPSS probability on internet-facing IIS hosts.
What it is
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe methods that permit remote command execution. Because the flaw is reachable over the network with no authentication, it is a full-compromise issue for any exposed IIS host running the affected component. The record is old and thin on technical detail, but the impact class is unambiguous.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the server, gaining full control of confidentiality, integrity and availability of the host.
Attack surface
Reached over the network via the RDS DataFactory interface exposed through IIS 3.x/4.x; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.7714 (99.5th percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Apply the Microsoft security bulletins MS98-004 and MS99-025 fixes, or upgrade to a supported IIS/MDAC release.
- Disable or remove the RDS DataFactory component and any unnecessary MDAC RDS handlers on IIS servers.
- Block external access to RDS/DataFactory endpoints at the firewall or reverse proxy.
- Retire or isolate IIS 3.x/4.x hosts, which are long past end of support.
- Restrict the IIS service account's privileges to limit command execution impact.
Detection
- Monitor IIS logs for requests to RDS/DataFactory handler paths, especially unusual or malformed method calls.
- Alert on unexpected child processes spawned by the IIS or MDAC service account.
- Review network traffic to RDS-related ports and endpoints for anomalous outbound connections from web servers.
- Audit servers for the presence of the RDS DataFactory component and flag any still exposed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-1999-1011 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-1999-1011), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.