CVE-1999-0886: Critical severity Microsoft Windows NT vulnerability
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify the RASMAN service security descriptor so non-privileged users cannot change the service configuration or point the service to an alternate binary/location via the Windows NT Service Control Manager. Grant modification rights only to administrative/system accounts.
RASMAN (Remote Access Connection Manager service) security descriptor / service DACL = restrict modification rights to administrative accounts - Compensating control
Restrict and monitor access to the Windows NT Service Control Manager to trusted administrator accounts (for example via local policy or administrative controls) and enable monitoring/alerting for changes to service configurations to detect attempts to repoint services.
- Operational
Audit the current RASMAN service ImagePath/binary location. If it points to an alternate or unauthorized location, restore the ImagePath to the legitimate system executable, remove unauthorized files placed at the alternate location, and restart the service. Investigate and remediate any signs of tampering.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0886?
CVE-1999-0886 is considered a moderate severity vulnerability affecting Windows NT 4.0.
How do I fix CVE-1999-0886?
To fix CVE-1999-0886, it is recommended to apply the latest service pack or security updates for Windows NT 4.0.
What systems are affected by CVE-1999-0886?
CVE-1999-0886 affects Microsoft Windows NT 4.0, including its various service packs.
What kind of attack is possible with CVE-1999-0886?
CVE-1999-0886 could allow attackers to exploit the RASMAN service to point to unauthorized locations.
Is there a workaround for CVE-1999-0886?
There are no specific workarounds documented for CVE-1999-0886, so applying patches is essential.