CVE-1999-0344: High severity Microsoft Windows NT vulnerability
NT users can gain debug-level access on a system process using the Sechole exploit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Revoke debug/program-debugging privileges from non-administrative NT user accounts and ensure only trusted administrators hold the ability to debug system processes (use local security policy / Group Policy User Rights Assignment to restrict the privilege).
Microsoft Windows NT Debug privileges (ability to obtain debug-level access to system processes) = restricted to trusted administrator accounts only - Compensating control
Apply host-based controls to limit exploitation risk: enable host intrusion prevention / application control to block unauthorized debugging tools and suspicious attempts to attach to system processes; isolate high-value systems and restrict interactive access for NT user accounts.
- Operational
Audit systems for signs of exploitation (look for unexpected debug/attach activity and related events), remediate any compromised hosts (investigate, remove malicious changes, and rebuild/reimage if necessary), and remove or remediate accounts found to have gained debug-level access.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0344?
CVE-1999-0344 is considered a high severity vulnerability that allows unauthorized debug-level access to system processes.
How do I fix CVE-1999-0344?
To fix CVE-1999-0344, it is recommended to apply the latest security patches provided by Microsoft for the affected versions of Windows NT.
Which versions of Windows NT are affected by CVE-1999-0344?
CVE-1999-0344 affects Windows NT versions 3.5.1 and 4.0.
What type of exploit is associated with CVE-1999-0344?
CVE-1999-0344 is associated with the Sechole exploit, which allows NT users to gain elevated access.
What technical measures can be taken to mitigate CVE-1999-0344?
Mitigation of CVE-1999-0344 can involve restricting user permissions and applying strict monitoring to detect unauthorized access.