CVE-1999-0670
Description
Buffer overflow in the Eyedog ActiveX control allows remote attackers to execute arbitrary commands via a crafted web page in Internet Explorer 4.0 and 5.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Buffer overflow in the Eyedog ActiveX control allows remote attackers to execute arbitrary commands via a crafted web page in Internet Explorer 4.0 and 5.0.
Vulnerability
A buffer overflow vulnerability exists in the Eyedog ActiveX control, which is a component of diagnostic software in Windows. The control was incorrectly marked as "safe for scripting" and is used by Internet Explorer. An affected version is present in Microsoft Internet Explorer versions 4.0 and 5.0 [1]. The flaw resides in one of the control's methods, which does not properly validate input length, allowing an attacker to overflow a buffer [1].
Exploitation
An attacker can craft a malicious web page that calls the vulnerable Eyedog control method with a specially crafted input. The attacker does not require any authentication or prior access beyond hosting a web page that a user visits with Internet Explorer. No user interaction beyond visiting the page is needed, as the control is marked as safe for scripting and loads automatically [1].
Impact
Successful exploitation allows a remote attacker to execute arbitrary commands on the victim's system with the privileges of the logged-in user. This can lead to full compromise of the affected machine, including data theft, installation of malware, or further lateral movement [1].
Mitigation
Microsoft released a security patch in Security Bulletin MS99-032 (originally posted August 31, 1999, updated March 21, 2003) that sets the "kill bit" for the Eyedog control, preventing it from loading within Internet Explorer [1]. Users should install the patch or apply the kill bit manually. There is no known workaround other than disabling the control or upgrading to a non-vulnerable version of Internet Explorer [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.