CVE-1999-0597: Critical severity Microsoft Windows NT vulnerability

Published Jan 1, 1999
·
Updated

A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.

Affected Software

1 affected component
Microsoft Windows NT

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure the Windows NT account policy to forcibly disconnect remote users when their logon hours expire (enable the policy that ends/terminates sessions at the end of allowed logon hours).

    Windows NT account policy forcibly disconnect remote users when logon hours expire = enabled

Event History

Jan 1, 1999
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeakness
Data Sourced
05:00 AM
Severity
Data Sourced
via NVD·05:00 AM
DescriptionSeverity
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

Which systems are affected in practice?

Windows NT servers that allow remote user sessions are exposed if their account policy does not forcibly disconnect those sessions when configured logon hours end.

2

What does an attacker need to exploit this issue?

An attacker needs valid remote access during an allowed logon period. If the session remains connected after the user's permitted hours expire, the account can continue accessing the server beyond the intended schedule.

3

How can I determine whether my server is affected?

Review the Windows NT account policy setting controlling whether remote users are forcibly disconnected when logon hours expire, and test whether an existing remote session is terminated at the configured end time.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203