CVE-1999-0292: Medium severity Microsoft Windows NT vulnerability
Denial of service through Winpopup using large user names.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Windows NT - Winpopupfrom your environment.Uninstall or remove the Winpopup/messenger component if it is not required on the system to eliminate the attack vector.
- Configuration
Disable or stop the Winpopup (messenger) service on affected Windows NT systems to prevent denial-of-service via large user names.
Microsoft Windows NT (Winpopup) Winpopup/messenger service = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0292?
CVE-1999-0292 is classified as a denial of service vulnerability.
How does CVE-1999-0292 exploit Winpopup?
CVE-1999-0292 exploits Winpopup by sending large user names, causing a denial of service.
What versions of Windows NT are affected by CVE-1999-0292?
CVE-1999-0292 affects Microsoft Windows NT versions 4.0 with Service Packs 1 and 2.
How can I mitigate the effects of CVE-1999-0292?
Mitigating CVE-1999-0292 can be accomplished by restricting the use of Winpopup or limiting user name lengths.
Is there a patch available for CVE-1999-0292?
No official patch exists for CVE-1999-0292, so affected systems should implement alternative mitigation strategies.