CVE-1999-0372: Infoleak
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the installer or add a post-installation step to securely delete or overwrite the reboot.ini setup file after installation so account names and passwords are not retained.
BackOffice Server installer remove_reboot_ini_after_install = true - Compensating control
Until reboot.ini is removed and credentials rotated, restrict filesystem access to the file to authorized administrators only and enable auditing of access to detect unauthorized reads; consider isolating affected systems from untrusted networks where practical.
- Operational
Locate and securely delete the reboot.ini setup file (file name: reboot.ini) created by the BackOffice Server installer on all systems where it exists.
- Operational
Rotate/change passwords for any accounts whose names and passwords were stored in reboot.ini; update and revoke any exposed credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0372?
CVE-1999-0372 is considered a high severity vulnerability due to the exposure of account names and passwords.
How do I fix CVE-1999-0372?
To fix CVE-1999-0372, ensure that the setup file reboot.ini is deleted after installation.
Which software versions are affected by CVE-1999-0372?
CVE-1999-0372 affects Microsoft BackOffice 4.0, Windows NT, and Windows 2000.
What type of data is exposed in CVE-1999-0372?
CVE-1999-0372 exposes account names and passwords stored in the reboot.ini setup file.
Is CVE-1999-0372 still relevant today?
While CVE-1999-0372 is an older vulnerability, it remains relevant for systems that have not been updated or secured.