CVE-1999-0580: Critical severity Microsoft Windows NT vulnerability
The HKEYLOCALMACHINE key in a Windows NT system has inappropriate, system-critical permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Review and correct the ACLs on HKEY_LOCAL_MACHINE to remove inappropriate permissions and restore the registry key to secure, system-critical permissions.
Windows registry (HKEY_LOCAL_MACHINE) permissions = restore to appropriate system-critical ACLs - Operational
After correcting permissions, audit affected systems to verify the ACL change and check for any unauthorized modifications under HKEY_LOCAL_MACHINE; if unauthorized activity is found, follow incident response procedures.
Event History
Frequently Asked Questions
Which systems are exposed?
Any Windows NT system where the HKEY_LOCAL_MACHINE registry key has the inappropriate permissions described is exposed. The issue affects a system-critical registry key, and the listed impact includes confidentiality, integrity, and availability.
What does an attacker need to exploit this issue?
The vector is network-based, attack complexity is low, and no authentication is required according to the supplied metrics. This indicates an unauthenticated remote attacker may be able to exploit the condition.
Is a default installation known to be affected?
The provided data does not state whether the affected permissions are present in a default Windows NT configuration. Verify the permissions assigned to HKEY_LOCAL_MACHINE on each Windows NT system.