CVE-1999-0589: Critical severity Microsoft Windows NT vulnerability
A system-critical Windows NT registry key has inappropriate permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove inappropriate permissions from the system-critical Windows NT registry key and restore secure/default ACLs so that only necessary privileged accounts have access. Document the change and apply it to the affected key.
Windows NT registry key permissions (ACL) = restore secure permissions / remove inappropriate access - Operational
After applying the ACL change, verify and audit the registry key permissions to confirm the fix and monitor for subsequent unauthorized modifications.
Event History
Frequently Asked Questions
Which systems should be checked?
Windows NT systems are affected where the system-critical registry key has inappropriate permissions. The provided information does not identify a specific Windows NT version, registry key, or configuration state.
What level of access does an attacker need and what is the potential impact?
The vulnerability is rated critical with network access, low attack complexity, and no authentication required in the supplied vector. It can affect confidentiality, integrity, and availability completely.