← Vulnerability feed

Vulnerability record · CVE-1999-1105 · published 31 December 1999

CVE-1999-1105: Microsoft windows 95 vulnerability

Microsoft · Windows 95

Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.

5.0 CVSS 2.0 Medium EPSS 22% · top 2.5%
5.0CVSS 2.0 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-1105 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1257Microsoft windows 2000 vulnerabilityMicrosoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that i…EPSS 15%10.0CVE-1999-0590Apple macos vulnerabilityA system does not present an appropriate legal message or warning to a user who is accessing it.EPSS 6.0%7.8CVE-2000-0305Beos vulnerabilityWindows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a l…EPSS 38%7.8CVE-1999-0387Microsoft windows 95 vulnerabilityA legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.EPSS 7.9%7.8CVE-1999-0918Microsoft windows 2000 improper input validation vulnerabilityDenial of service in various Windows systems via malformed, fragmented IGMP packets.EPSS 26%7.6CVE-1999-1593Microsoft windows 2000 link following vulnerabilityWindows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch regist…EPSS 18%7.6CVE-2000-0330Microsoft windows 95 vulnerabilityThe networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access UR…EPSS 15%7.5CVE-2002-1260Microsoft windows 2000 vulnerabilityThe Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks an…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-1999-1105), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.