CVE-1999-0224: Medium severity Microsoft Windows NT vulnerability
Denial of service in Windows NT messenger service through a long username.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Stop and disable the Messenger service (for example, via Services MMC or 'net stop messenger' and set startup type to Disabled) to mitigate denial-of-service via long usernames.
Microsoft Windows NT Messenger service enabled = false - Compensating control
Block or filter access to the Messenger service from untrusted networks at the perimeter or host firewall to prevent remote exploitation of the vulnerable service.
- Operational
Monitor vendor/security advisories for Microsoft Windows NT and apply any available patches or fixes addressing this Messenger service vulnerability as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0224?
CVE-1999-0224 is classified as a high severity vulnerability due to its potential to cause denial of service in Windows NT.
How do I fix CVE-1999-0224?
To fix CVE-1999-0224, it is recommended to apply the latest patches or service packs provided by Microsoft for Windows NT 4.0.
What versions of Windows NT are affected by CVE-1999-0224?
CVE-1999-0224 affects various versions of Windows NT 4.0, including all service pack levels from SP1 to SP5.
What kind of attack does CVE-1999-0224 entail?
CVE-1999-0224 involves a denial of service attack that can be executed through a long username in the Windows NT messenger service.
Can CVE-1999-0224 be exploited remotely?
Yes, CVE-1999-0224 can be exploited remotely by an attacker who can send a specially crafted request to the vulnerable service.