First published: Tue Nov 30 1999(Updated: )
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp5 | |
=4.0 | ||
=4.0-sp1 | ||
=4.0-sp2 | ||
=4.0-sp3 | ||
=4.0-sp4 | ||
=4.0-sp5 | ||
=4.0-sp6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0824 allows a Windows NT user to map a drive letter to a folder using SUBST, which may not be unmapped after logout, posing a risk for later users.
CVE-1999-0824 affects all versions of Microsoft Windows NT 4.0, including service packs SP1 through SP6.
The risks of CVE-1999-0824 include unauthorized access and modification of files in folders accessed by future users.
To mitigate CVE-1999-0824, ensure that users are not allowed to use the SUBST command or consider logging off users properly to clear mapped drives.
There is no specific patch for CVE-1999-0824, but best practices in user management can help mitigate the risks.