CVE-1999-1358

CVSS 2.0 Score 4.6 of 10 (medium)

Details

Published Dec 31, 1999
Updated: Sep 5, 2008

Summary

CVE-1999-1358 is a vulnerability affecting Windows NT and Windows 2000 systems. When an administrator modifies a user policy, the update fails if the local ntconfig.pol file is not writable by the user. This allows local users to bypass certain policy restrictions, potentially rendering them ineffective. The vulnerability could be exploited by changing the policy file to read-only, thereby evading the intended access controls.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows NT
  • Microsoft Windows 2000

Affected Vendors

  • Microsoft