CVE-1999-0886: Critical severity Microsoft Windows NT vulnerability

Published Sep 17, 1999
·
Updated

The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

Affected Software

6 affected components
Microsoft Windows NT=4.0
Microsoft Windows NT=4.0-sp2
Microsoft Windows NT=4.0-sp1
Microsoft Windows NT=4.0-sp4
Microsoft Windows NT=4.0-sp3
Microsoft Windows NT=4.0-sp5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Modify the RASMAN service security descriptor so non-privileged users cannot change the service configuration or point the service to an alternate binary/location via the Windows NT Service Control Manager. Grant modification rights only to administrative/system accounts.

    RASMAN (Remote Access Connection Manager service) security descriptor / service DACL = restrict modification rights to administrative accounts
  2. Compensating control

    Restrict and monitor access to the Windows NT Service Control Manager to trusted administrator accounts (for example via local policy or administrative controls) and enable monitoring/alerting for changes to service configurations to detect attempts to repoint services.

  3. Operational

    Audit the current RASMAN service ImagePath/binary location. If it points to an alternate or unauthorized location, restore the ImagePath to the legitimate system executable, remove unauthorized files placed at the alternate location, and restart the service. Investigate and remediate any signs of tampering.

Event History

Sep 17, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0886?

CVE-1999-0886 is considered a moderate severity vulnerability affecting Windows NT 4.0.

2

How do I fix CVE-1999-0886?

To fix CVE-1999-0886, it is recommended to apply the latest service pack or security updates for Windows NT 4.0.

3

What systems are affected by CVE-1999-0886?

CVE-1999-0886 affects Microsoft Windows NT 4.0, including its various service packs.

4

What kind of attack is possible with CVE-1999-0886?

CVE-1999-0886 could allow attackers to exploit the RASMAN service to point to unauthorized locations.

5

Is there a workaround for CVE-1999-0886?

There are no specific workarounds documented for CVE-1999-0886, so applying patches is essential.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203