CVE-1999-0535: Critical severity Microsoft Windows NT vulnerability
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Adjust the account policy to require a sufficiently long minimum password length (increase the minimum password length to meet organizational security requirements).
Microsoft Windows NT / Windows 2000 account policy password length = configure an appropriate minimum password length - Configuration
Set the maximum password age in the account policy so passwords must be changed periodically according to organizational policy.
Microsoft Windows NT / Windows 2000 account policy password age = configure a maximum password age to require periodic changes - Configuration
Enable and configure password history/uniqueness in the account policy so users cannot reuse recent passwords.
Microsoft Windows NT / Windows 2000 account policy password uniqueness = enforce password history / uniqueness to prevent reuse
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0535?
CVE-1999-0535 has a high severity as it involves critical password policy settings that can lead to weak password practices.
How do I fix CVE-1999-0535?
To fix CVE-1999-0535, adjust the Windows NT account policy settings for password length, age, and uniqueness to enforce stronger security standards.
Who is affected by CVE-1999-0535?
CVE-1999-0535 affects users of Microsoft Windows NT and Microsoft Windows 2000 systems.
What can happen if I ignore CVE-1999-0535?
Ignoring CVE-1999-0535 can result in increased risk of unauthorized access due to weak password policies.
Is CVE-1999-0535 still relevant today?
While CVE-1999-0535 was identified in 1999, its implications may still be relevant for legacy systems using outdated password policies.