CVE-1999-0726: Input Validation
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Prevent users and services from executing untrusted or unverified program files. Enforce a policy that only allows execution of binaries from trusted locations/accounts and deny execution of programs obtained from untrusted sources.
Microsoft Windows NT and Microsoft Windows 2000 execution of untrusted executables = disabled/deny - Compensating control
Mitigate risk by restricting delivery and execution of potentially malicious executables: block or quarantine executable attachments and downloads, restrict access to removable media and network shares, and limit which accounts can run arbitrary binaries. Ensure only trusted administrators may install or run new programs.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0726?
CVE-1999-0726 is classified as a high-severity vulnerability due to its potential to cause a denial of service.
How can I mitigate CVE-1999-0726?
To mitigate CVE-1999-0726, it is recommended to apply any available patches from Microsoft and to refrain from executing untrusted programs.
Which systems are affected by CVE-1999-0726?
CVE-1999-0726 primarily affects Microsoft Windows NT 4.0 and Windows 2000 operating systems.
What is the impact of CVE-1999-0726?
The impact of CVE-1999-0726 is that an attacker can exploit the vulnerability to crash the system, leading to a denial of service.
Is CVE-1999-0726 exploitable remotely?
Yes, CVE-1999-0726 can be exploited remotely if the attacker has access to execute a malformed file.