CVE-1999-0664: Critical severity Microsoft Windows NT vulnerability
An application-critical Windows NT registry key has inappropriate permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Review and correct the ACL on the identified application-critical Windows NT registry key. Remove broad or unneeded user/group entries and ensure only required system accounts and administrators have access. Apply least-privilege permissions and appropriate inheritance settings using regedit, security policy tools, or enterprise configuration management.
Windows NT registry key (application-critical) permissions/ACL = restrict permissions to required system and administrative accounts - Operational
Audit and review recent accesses and modifications to the registry key to detect unauthorized changes. If unauthorized modifications are found or compromise is suspected, restore the registry key from a known-good backup and perform incident response actions (e.g., investigate scope, remediate affected systems, and rotate any credentials that may have been exposed).
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Microsoft Windows NT systems are affected when an application-critical registry key has inappropriate permissions.
What level of access does an attacker need to exploit it?
The provided vector indicates network access with low attack complexity and no authentication requirement.
What security impact can exploitation have?
The supplied severity vector indicates complete compromise of confidentiality, integrity, and availability.
How can I determine whether a system is affected?
Review permissions on application-critical Windows NT registry keys and identify keys that grant inappropriate access.