CVE-1999-0726: Input Validation

Published Jun 30, 1999
·
Updated

An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.

Affected Software

5 affected components
Microsoft Windows NT=4.0
Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows NT=4.0-sp4
Microsoft Windows NT=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Prevent users and services from executing untrusted or unverified program files. Enforce a policy that only allows execution of binaries from trusted locations/accounts and deny execution of programs obtained from untrusted sources.

    Microsoft Windows NT and Microsoft Windows 2000 execution of untrusted executables = disabled/deny
  2. Compensating control

    Mitigate risk by restricting delivery and execution of potentially malicious executables: block or quarantine executable attachments and downloads, restrict access to removable media and network shares, and limit which accounts can run arbitrary binaries. Ensure only trusted administrators may install or run new programs.

Event History

Jun 30, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0726?

CVE-1999-0726 is classified as a high-severity vulnerability due to its potential to cause a denial of service.

2

How can I mitigate CVE-1999-0726?

To mitigate CVE-1999-0726, it is recommended to apply any available patches from Microsoft and to refrain from executing untrusted programs.

3

Which systems are affected by CVE-1999-0726?

CVE-1999-0726 primarily affects Microsoft Windows NT 4.0 and Windows 2000 operating systems.

4

What is the impact of CVE-1999-0726?

The impact of CVE-1999-0726 is that an attacker can exploit the vulnerability to crash the system, leading to a denial of service.

5

Is CVE-1999-0726 exploitable remotely?

Yes, CVE-1999-0726 can be exploited remotely if the attacker has access to execute a malformed file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203