cbcvebase.
CVE-1999-1246
published 1999-12-31

CVE-1999-1246: Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure…

PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
9.21%
94.7th percentile
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftsite_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.