CVE-1999-1317

CVSS 2.0 Score 4.6 of 10 (medium)

Details

Published Dec 31, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-1317 is a vulnerability affecting Windows NT 4.0 SP4 and earlier versions. This issue grants local users the ability to elevate privileges by manipulating symbolic links in the \\?? object folder. By leveraging different case letters (either upper or lower) to point to distinct devices, attackers can exploit this vulnerability to gain unauthorized access to sensitive system information or execute malicious code with elevated privileges. This security weakness poses a serious risk to system integrity and confidentiality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows NT

Affected Vendors

  • Microsoft