CVE-1999-0654: Critical severity Microsoft Windows NT vulnerability
The OS/2 or POSIX subsystem in NT is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the OS/2 subsystem on the NT system (turn off the OS/2 subsystem feature/service).
NT OS/2 subsystem enabled = false - Configuration
Disable the POSIX subsystem on the NT system (turn off the POSIX subsystem feature/service).
NT POSIX subsystem enabled = false
Event History
Frequently Asked Questions
Which systems should be prioritized for triage?
Windows NT systems with either the OS/2 or POSIX subsystem enabled are the affected population identified by the available data. The supplied vector indicates network reachability, low attack complexity, and no authentication requirement.
What level of attacker access and impact does the available assessment indicate?
The available data indicates an unauthenticated attacker can exploit the issue over a network with low complexity. It also rates the potential impact as complete compromise of confidentiality, integrity, and availability.
How can I determine whether a host is affected?
Check whether the OS/2 subsystem or POSIX subsystem is enabled on the Windows NT host. Their presence is the condition identified in the available data.