CVE-1999-0597: Critical severity Microsoft Windows NT vulnerability
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the Windows NT account policy to forcibly disconnect remote users when their logon hours expire (enable the policy that ends/terminates sessions at the end of allowed logon hours).
Windows NT account policy forcibly disconnect remote users when logon hours expire = enabled
Event History
Frequently Asked Questions
Which systems are affected in practice?
Windows NT servers that allow remote user sessions are exposed if their account policy does not forcibly disconnect those sessions when configured logon hours end.
What does an attacker need to exploit this issue?
An attacker needs valid remote access during an allowed logon period. If the session remains connected after the user's permitted hours expire, the account can continue accessing the server beyond the intended schedule.
How can I determine whether my server is affected?
Review the Windows NT account policy setting controlling whether remote users are forcibly disconnected when logon hours expire, and test whether an existing remote session is terminated at the configured end time.