VYPR
Unrated severityNVD Advisory· Published Aug 5, 1997· Updated Apr 16, 2026

CVE-1999-1446

CVE-1999-1446

Description

Internet Explorer 3 fails to clear history DAT files when users select Clear History, leaving visited URLs exposed to local attackers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Internet Explorer 3 fails to clear history DAT files when users select Clear History, leaving visited URLs exposed to local attackers.

Vulnerability

Internet Explorer 3 records a history of all visited URLs in .DAT files located in the Temporary Internet Files and History folders (e.g., MM2048.DAT, MM256.DAT). When the user selects the 'Clear History' option via View/Options/Navigation, the files are not actually cleared; the history entries remain intact. The operating system's tailored display also hides these files from normal folder browsing, giving users a false sense of security. Affected versions include Internet Explorer 3 on Windows NT 4.0 and likely other platforms [1][2].

Exploitation

An attacker with local access to the system can navigate to the Temporary Internet Files or History folders and use any binary editor or simple commands (e.g., TYPE) to read the .DAT files. No special tools or privileges are required beyond physical or remote desktop access. The references confirm that a standard directory listing shows the folders as empty, but the .DAT files are present and readable [1][2].

Impact

Successful reading of these .DAT files reveals every URL the user has visited, including search queries and uploaded/downloaded content. This constitutes a significant information disclosure vulnerability, exposing the user's browsing history and potentially sensitive data (e.g., search terms submitted to web forms) to anyone with local system access [1][2].

Mitigation

Microsoft acknowledged the issue in a TechNet article, which advised users to warn about the dangers of snooping but did not provide a fix. No patched version of Internet Explorer 3 was released. As of the publication date, no workaround other than manually deleting the .DAT files (which may be denied access) or upgrading to a newer browser version is available [1]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*
    • (no CPE)range: =3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.