CVE-1999-0519: High severity Microsoft Outlook vulnerability
A NETBIOS/SMB share password is the default, null, or missing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure each SMB/NetBIOS share to require and use a non-default, non-empty password. Replace any default, null, or missing share passwords with unique, strong credentials.
SMB/NetBIOS share share_password = non-default, non-empty strong password - Configuration
Disable anonymous/null sessions and guest access for SMB/NetBIOS shares so that all access requires authentication.
SMB/NetBIOS anonymous_access / guest_account = disabled - Compensating control
Restrict access to SMB/NetBIOS shares to trusted hosts or networks using firewall rules or network ACLs; isolate shares from untrusted networks until proper authentication is enforced.
- Operational
Audit all systems for SMB/NetBIOS shares with default, null, or missing passwords and remediate them by applying the required configuration changes; notify relevant owners and, if needed, rotate any credentials that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0519?
CVE-1999-0519 is classified as a high-severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-1999-0519?
To fix CVE-1999-0519, configure all NETBIOS/SMB share passwords to be strong and non-null.
What software is affected by CVE-1999-0519?
CVE-1999-0519 affects Microsoft Outlook 2000, Microsoft Windows NT, Windows 2000, and Windows 95.
What are the risks associated with CVE-1999-0519?
The risks associated with CVE-1999-0519 include unauthorized access to sensitive data and resources due to weak share password configurations.
Is CVE-1999-0519 still relevant today?
While CVE-1999-0519 pertains to older systems, it highlights the importance of security hygiene in password management that is still relevant today.