CVE-1999-0596: Critical severity Microsoft Windows NT vulnerability
A Windows NT log file has an inappropriate maximum size or retention period.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Adjust the Windows NT event/log file maximum size and retention period to appropriate values to prevent excessive growth or inadequate retention. Configure these settings via the system's Event Viewer or central log management/group policy according to your organizational logging policy.
Windows NT log file (Event Log) maximum_size / retention_period = set to appropriate values for your environment
Event History
Frequently Asked Questions
Which systems should be reviewed for this issue?
Windows NT systems are affected when their log files are configured with an inappropriate maximum size or retention period. The provided data does not identify specific Windows NT versions, log types, or configuration values.
What level of attacker access is required?
An attacker does not need authentication and can exploit the issue remotely, according to the CVSS vector. The provided data does not describe the specific attack steps or required access to the affected logs.
What can be done if patching is not immediately possible?
Review Windows NT log file maximum-size and retention settings and correct configurations that are inappropriate for the environment. No vendor patch, workaround, or recommended setting is provided in the available data.