CVE-1999-0496

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Jan 1, 1997
Updated: Nov 20, 2024
CWE ID 264

Summary

CVE-1999-0496 is a vulnerability affecting Windows NT 4.0 systems. It allows a user to elevate their privileges to administrative levels, bypassing the standard permission structure. The issue stems from NtOpenProcessToken, a function that can be manipulated to succeed even when the user does not have the necessary permissions. This vulnerability, also known as "GetAdmin," poses a significant risk, enabling unauthorized users to gain administrative control over the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows NT

Affected Vendors

  • Microsoft