← CVE catalog

CVE-1999-0493

High CVSS 7.5

Published 1999-06-07 ยท last changed 2026-06-16

The fix

We hold no Microsoft remediation data for CVE-1999-0493, which normally means it is not a Windows CVE. For non-Microsoft software the fix is the vendor's own updated release, and the affected versions are listed below.

What it is

rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.

Sources

CVSS vector: AV:N/AC:L/Au:N/C:P/I:P/A:P