CVE-1999-0535: Critical severity Microsoft Windows NT vulnerability

Published Jan 1, 1997
·
Updated

A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.

Affected Software

2 affected components
Microsoft Windows NT
Microsoft Windows 2000

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Adjust the account policy to require a sufficiently long minimum password length (increase the minimum password length to meet organizational security requirements).

    Microsoft Windows NT / Windows 2000 account policy password length = configure an appropriate minimum password length
  2. Configuration

    Set the maximum password age in the account policy so passwords must be changed periodically according to organizational policy.

    Microsoft Windows NT / Windows 2000 account policy password age = configure a maximum password age to require periodic changes
  3. Configuration

    Enable and configure password history/uniqueness in the account policy so users cannot reuse recent passwords.

    Microsoft Windows NT / Windows 2000 account policy password uniqueness = enforce password history / uniqueness to prevent reuse

Event History

Jan 1, 1997
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0535?

CVE-1999-0535 has a high severity as it involves critical password policy settings that can lead to weak password practices.

2

How do I fix CVE-1999-0535?

To fix CVE-1999-0535, adjust the Windows NT account policy settings for password length, age, and uniqueness to enforce stronger security standards.

3

Who is affected by CVE-1999-0535?

CVE-1999-0535 affects users of Microsoft Windows NT and Microsoft Windows 2000 systems.

4

What can happen if I ignore CVE-1999-0535?

Ignoring CVE-1999-0535 can result in increased risk of unauthorized access due to weak password policies.

5

Is CVE-1999-0535 still relevant today?

While CVE-1999-0535 was identified in 1999, its implications may still be relevant for legacy systems using outdated password policies.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203