CVE-1999-0581: Critical severity Microsoft Windows NT vulnerability
The HKEYCLASSESROOT key in a Windows NT system has inappropriate, system-critical permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Review and modify the ACLs on HKEY_CLASSES_ROOT to remove inappropriate or overly permissive entries. Grant access only to required system-level principals and authorized administrators; remove non-essential accounts and groups from the key's permissions.
Windows Registry (HKEY_CLASSES_ROOT) ACL/permissions = restrict to only required system and administrative principals - Operational
Audit all Windows NT systems to identify instances where HKEY_CLASSES_ROOT permissions are incorrect. For each affected system, document the current ACLs, apply the corrected permissions, and verify system functionality after the change. Maintain records of changes for future review.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0581?
CVE-1999-0581 has a high severity due to its potential impact on system security.
What systems are affected by CVE-1999-0581?
CVE-1999-0581 affects Microsoft Windows NT systems.
How do I fix CVE-1999-0581?
To fix CVE-1999-0581, you should modify the permissions of the HKEY_CLASSES_ROOT registry key to ensure appropriate access controls.
What type of vulnerability is CVE-1999-0581?
CVE-1999-0581 is a permission vulnerability that allows unauthorized access to critical system components.
Who is responsible for addressing CVE-1999-0581?
It is the responsibility of system administrators and IT professionals to address CVE-1999-0581 by applying security policies.