CVE-1999-0592: Critical severity Microsoft Windows NT vulnerability
Published Jan 1, 1999
·Updated
The Logon box of a Windows NT system displays the name of the last user who logged in.
Affected Software
1 affected component
Microsoft Windows NT
Event History
Jan 1, 1999
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeakness
Data Sourced
05:00 AM
Severity
Data Sourced
via NVD·05:00 AM
DescriptionSeverity
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
Who can obtain the disclosed information?
Windows NT systems that expose the Logon box to unauthorized users are affected because it displays the name of the last successful user. This can disclose a valid account name to anyone who can view the logon screen.
2
What does an attacker need to exploit this issue?
An attacker does not need authentication or a complex attack path; they only need access to view the Windows NT Logon box. The disclosed username may assist subsequent attempts to authenticate to the system.