CVE-1999-1011

CRITICAL ⚠ Exploit

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

Affects 4 products across 1 vendor.

BCS8.98
CVSS 2.010.0
EPSS77.1%
Percentile100th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

The Remote Data Service (RDS) DataFactory component in Microsoft Data Access Components (MDAC) for IIS 3.x and 4.x exposes unsafe methods that can be exploited by remote attackers to execute arbitrary commands, leading to potential system compromise.

BSID: BS-1999-GLOBAL-171515-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-1999-1011?
The Remote Data Service (RDS) DataFactory component in Microsoft Data Access Components (MDAC) for IIS 3.x and 4.x exposes unsafe methods that can be exploited by remote attackers to execute arbitrary commands, leading to potential system compromise.
What is the CVSS score for CVE-1999-1011?
CVE-1999-1011 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 77.1%.
Is CVE-1999-1011 actively exploited?
Public exploit available for CVE-1999-1011. Exploitation risk elevated.
How do I remediate CVE-1999-1011?
Priority: IMMEDIATE.
What systems are affected by CVE-1999-1011?
CVE-1999-1011 affects: Microsoft, Microsoft, Microsoft, Microsoft.
Vulnerability Details
CVE IDCVE-1999-1011
BSIDBS-1999-GLOBAL-171515-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published1999-07-19
Last Modified2026-06-16
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Attackers can exploit unsafe methods in the RDS DataFactory component to execute arbitrary commands on the server. This can be achieved by sending specially crafted requests to the affected server.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Microsoft Internet Information Server
Microsoft Site Server
Microsoft Index Server
Microsoft Data Access Components
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 9876 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Microsoft
CVE-1999-0385 10.0 The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a re... CVE-1999-0535 10.0 A Windows NT account policy for passwords has inappropriate, security-critica... CVE-1999-1241 10.0 Internet Explorer, with a security setting below Medium, allows remote attack... CVE-2000-0788 10.0 The Mail Merge tool in Microsoft Word does not prompt the user before executi... CVE-2000-1034 10.0 Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows ...
View all Microsoft CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →