CVE-1999-1217: Medium severity Microsoft Windows NT vulnerability

Published Jul 25, 1997
·
Updated

The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.

Affected Software

1 affected component
Microsoft Windows NT

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove the '.' entry from the system PATH so the current working directory is not searched. Update the system PATH environment variable (via System Properties or the registry) to exclude '.' and ensure changes apply to new sessions.

    Microsoft Windows NT (system PATH) include_current_working_directory (.) = remove
  2. Configuration

    Ensure directories where system programs are launched are not writable by non-privileged local users. Remove write permissions for standard users and allow only trusted administrators to create or modify executables in those directories.

    Windows NT system program directories directory write permissions = restrict to administrators
  3. Operational

    Audit systems for Trojan horse programs: search for unauthorized executables whose names match commonly used system program names in directories accessible to local users, remove any confirmed malicious binaries, and restore legitimate files from trusted backups or installation media.

Event History

Jul 25, 1997
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1217?

CVE-1999-1217 is considered a high-risk vulnerability due to the potential for local users to exploit it for unauthorized privilege escalation.

2

How do I fix CVE-1999-1217?

Fixing CVE-1999-1217 involves modifying the system PATH variable to exclude the current working directory or implementing strict access controls.

3

Who is affected by CVE-1999-1217?

Any user operating Windows NT is potentially affected by CVE-1999-1217 if the current working directory is included in the PATH.

4

What type of attack is associated with CVE-1999-1217?

CVE-1999-1217 is associated with local privilege escalation attacks, where attackers can replace system programs with malicious versions.

5

Is there a workaround for CVE-1999-1217?

Yes, a workaround for CVE-1999-1217 includes avoiding the use of the current directory in the PATH for non-administrative users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203