VYPR
Unrated severityNVD Advisory· Published Nov 14, 1999· Updated Apr 16, 2026

CVE-1999-1110

CVE-1999-1110

Description

Windows Media Player ActiveX in IE 5.0 leaks file existence via error codes, allowing remote sites to probe client files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Windows Media Player ActiveX in IE 5.0 leaks file existence via error codes, allowing remote sites to probe client files.

Vulnerability

The Windows Media Player ActiveX control, included with Internet Explorer 5.0, returns a specific error code when attempting to load a non-existent file. This behavior allows a remote malicious website to determine the existence of files on the client machine. This vulnerability affects Internet Explorer 5.0 [1].

Exploitation

An attacker can host a malicious website that uses the Windows Media Player ActiveX control. By instructing the control to attempt to load a specific file path on the victim's client machine and observing the returned ErrorCode, the attacker can deduce whether the file exists or not. This requires the user to visit the attacker's website [1].

Impact

Successful exploitation allows a remote attacker to determine the existence of arbitrary files on the client's file system. This information can be used to infer user names, system configurations, and potentially discover sensitive files, although direct access to file contents is not provided [1].

Mitigation

No specific patch or fixed version information is available in the provided references. Users are advised to exercise caution when visiting untrusted websites. It is recommended to disable or remove the Windows Media Player ActiveX control if not essential for browsing [1].

AI Insight generated on Jun 6, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.