CVE-1999-1370
published 1999-03-23CVE-1999-1370: The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a…
PriorityP414high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.34%
68.2th percentile
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Internet Explorer 5.0 Setup Wizard ie5setup.exe privileges management
vuldb·2026-04-19·CVSS 7.2
CVE-1999-1370 [HIGH] Microsoft Internet Explorer 5.0 Setup Wizard ie5setup.exe privileges management
A vulnerability has been found in Microsoft Internet Explorer 5.0 and classified as problematic. This affects an unknown part of the file ie5setup.exe of the component Setup Wizard. Performing a manipulation results in improper privilege management.
This vulnerability is reported as CVE-1999-1370. The attack requires a local approach. Moreover, an exploit is present.
The affected component should be upgraded.
GHSA
GHSA-grpf-xfq7-g359: The setup wizard (ie5setup
ghsa_unreviewed·2022-04-30
CVE-1999-1370 [HIGH] GHSA-grpf-xfq7-g359: The setup wizard (ie5setup
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1999-03-23
Published