CVE-1999-0380

CVSS 2.0 Score 4.6 of 10 (medium)

Details

Published Feb 25, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0380 is a vulnerability affecting SLMail versions 3.1 and 3.2. This issue allows local users to access any file in the NTFS file system, by setting a user's Finger File to point to the target file and running the Finger command. The Remote Administration Service (RAS) must be enabled for this exploit to work. This vulnerability poses a significant risk, as it grants unauthorized access to sensitive files. Users are advised to disable the RAS and update their SLMail software to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share