CVE-1999-0391: High severity Microsoft Terminal Server vulnerability
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Windows 95 and Windows 98from your environment.Retire or remove Windows 95 and Windows 98 systems from your environment; these OSs are vulnerable because SMB authentication challenges can be replayed, allowing impersonation.
- Compensating control
If immediate removal is not possible, isolate systems running Windows 95 and Windows 98 or restrict their network access to trusted hosts only (for example using VLANs, firewall rules or access control lists) to reduce exposure to SMB authentication replay attacks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0391?
CVE-1999-0391 is classified as a medium severity vulnerability due to its potential for allowing user impersonation.
How do I fix CVE-1999-0391?
To mitigate CVE-1999-0391, it's recommended to disable SMB authentication in affected legacy systems or update to more secure operating systems.
Which operating systems are affected by CVE-1999-0391?
CVE-1999-0391 affects Microsoft Windows 95, Windows 98, and various versions of Windows NT and Windows 2000.
Can CVE-1999-0391 be exploited remotely?
Yes, CVE-1999-0391 can be exploited remotely if an attacker is able to intercept the SMB authentication process.
What are the consequences of exploiting CVE-1999-0391?
Exploiting CVE-1999-0391 can allow an attacker to impersonate legitimate users, potentially gaining unauthorized access to sensitive resources.