CVE-2010-1899
CVE-2010-1899 is a medium-severity vulnerability in Microsoft Internet Information Server with a CVSS 2.0 base score of 4.3. Its EPSS exploit-prediction score of 57% places it in the 99th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-119.
Key facts
- Severity: Medium (CVSS 2.0 base score 4.3)
- EPSS exploit prediction: 57% (99th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: Microsoft Internet Information Server
- Published:
- Last modified:
Description
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."
Frequently asked questions
- What is CVE-2010-1899?
- Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."
- How severe is CVE-2010-1899?
- CVE-2010-1899 has a CVSS 2.0 base score of 4.3, rated medium severity.
- Is CVE-2010-1899 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 57% (99th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2010-1899?
- CVE-2010-1899 primarily affects Microsoft Internet Information Server. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2010-1899?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2010-1899 published?
- CVE-2010-1899 was published on 2010-09-15 and last updated on 2026-06-16.
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-065
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7127
Affected products (2)
- cpe:2.3:a:microsoft:internet_information_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_information_services:7.5:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Internet Information Server
- CVE-2008-0075 — Critical (CVSS 10.0): Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to…
- CVE-2001-0500 — Critical (CVSS 10.0): Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier…
- CVE-1999-1011 — Critical (CVSS 10.0): The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x…
- CVE-1999-0874 — Critical (CVSS 10.0): Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with…
- CVE-1999-0407 — Critical (CVSS 10.0): By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force…
- CVE-1999-1376 — Critical (CVSS 10.0): Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary…
All CVEs affecting Microsoft Internet Information Server →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-77946 — Critical (CVSS 10.0): A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function…
- CVE-2026-76008 — Critical (CVSS 10.0): A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file…
- CVE-2026-75784 — Critical (CVSS 10.0): A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of…
- CVE-2026-74843 — Critical (CVSS 10.0): A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function…
- CVE-2026-16367 — Critical (CVSS 10.0): Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox…
- CVE-2026-2778 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in…
Threat intelligence
Threat-intel indicators referencing this CVE:
- 120.79.96.4 (ipv4-addr)
- 82.199.197.245 (ipv4-addr)
- 61.145.163.164 (ipv4-addr)
- 47.236.247.176 (ipv4-addr)
- 175.178.123.119 (ipv4-addr)
- 39.105.15.222 (ipv4-addr)
- 183.230.155.13 (ipv4-addr)
- 51.178.100.208 (ipv4-addr)