CVE-1999-0366: High severity Microsoft Windows NT vulnerability
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove the affected component from your environment.
If Service Pack 4 for Windows NT 4.0 is the cause and reverting is acceptable, consider uninstalling Service Pack 4 for Windows NT 4.0 to remove the condition that allows blank-password network access.
- Configuration
Disable acceptance of blank passwords for network authentication and ensure account policies prevent blank/empty passwords for any account that can access network shares.
Microsoft Windows NT 4.0 network_blank_passwords_allowed = false - Compensating control
Restrict network access to file shares (SMB) using network controls: block or filter file-sharing ports at the network boundary, restrict share access to trusted IP ranges, and isolate vulnerable Windows NT hosts until remediated.
- Operational
Audit all user and service accounts on Windows NT hosts for blank or empty passwords and set strong non-blank passwords for any account found. Review and restrict share permissions where accounts with blank passwords previously had access.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0366?
CVE-1999-0366 is considered a moderate severity vulnerability due to the risk of unauthorized access to network shares.
How do I fix CVE-1999-0366?
To fix CVE-1999-0366, update your Windows NT 4.0 system to a version without this vulnerability or apply security patches provided by Microsoft.
What systems are affected by CVE-1999-0366?
CVE-1999-0366 affects systems running Microsoft Windows NT 4.0 with Service Pack 4 installed.
Can CVE-1999-0366 be exploited remotely?
Yes, CVE-1999-0366 can potentially be exploited remotely if the network shares are accessible over the network.
What types of attacks can be executed using CVE-1999-0366?
An attacker can gain unauthorized access to files on network shares due to the vulnerability in CVE-1999-0366.