CVE-1999-0572: Critical severity Microsoft Windows NT vulnerability
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove or change the association of .reg files with the Windows registry editor (regedit) so that double-clicking a .reg file does not automatically import it into the registry. Require explicit, verified manual execution/import of registry files.
Microsoft Windows (file association) .reg file association = disassociate from regedit / do not auto-open - Compensating control
Treat .reg files from untrusted sources as suspicious: block or quarantine .reg attachments at gateway/email filters, scan them with antivirus/antimalware before any handling, and instruct users not to open or run .reg files unless their origin is verified.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0572?
CVE-1999-0572 is considered a medium severity vulnerability due to the potential for Trojan Horse attacks on the registry.
How do I fix CVE-1999-0572?
To mitigate CVE-1999-0572, avoid using .reg files from untrusted sources and implement strict user permissions for registry access.
Which software is affected by CVE-1999-0572?
CVE-1999-0572 affects Microsoft Windows NT and Microsoft Windows 2000.
What are the risks associated with CVE-1999-0572?
The risks of CVE-1999-0572 include unauthorized modification of the system registry, potentially leading to malware execution.
Is CVE-1999-0572 still a concern today?
While CVE-1999-0572 is an older vulnerability, it remains a concern for systems still running unsupported versions of Windows NT or Windows 2000.