CVE-1999-1317
CVSS 2.0 Score 4.6 of 10 (medium)
Details
Published Dec 31, 1999
Updated: Nov 20, 2024
Summary
CVE-1999-1317 is a vulnerability affecting Windows NT 4.0 SP4 and earlier versions. This issue grants local users the ability to elevate privileges by manipulating symbolic links in the \\?? object folder. By leveraging different case letters (either upper or lower) to point to distinct devices, attackers can exploit this vulnerability to gain unauthorized access to sensitive system information or execute malicious code with elevated privileges. This security weakness poses a serious risk to system integrity and confidentiality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows NT
Affected Vendors
- Microsoft