CVE-1999-1294: Low severity Microsoft Windows NT vulnerability

Published Dec 31, 1999
·
Updated

Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.

Affected Software

1 affected component
Microsoft Windows NT=3.51

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Microsoft/Office Shortcut Bar (OSB) from your environment.

    Uninstall or remove the Office Shortcut Bar if it is not required on affected systems.

  2. Configuration

    Disable the Office Shortcut Bar to prevent it from enabling backup and restore permissions that are inherited by programs started from the Shortcut Bar.

    Office Shortcut Bar (OSB) enabled = false
  3. Operational

    Do not launch File Manager or other programs from the Office Shortcut Bar; launch them directly to avoid inheriting backup/restore permissions.

Event History

Dec 31, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1294?

CVE-1999-1294 has a moderate severity as it allows local users to gain unauthorized access to certain folders.

2

How do I fix CVE-1999-1294?

To fix CVE-1999-1294, ensure that proper access control and permissions are configured for the Office Shortcut Bar in Windows 3.51.

3

Who is affected by CVE-1999-1294?

CVE-1999-1294 affects users of Microsoft Windows NT 3.51 who utilize the Office Shortcut Bar.

4

What type of vulnerability is CVE-1999-1294?

CVE-1999-1294 is a local privilege escalation vulnerability.

5

Can CVE-1999-1294 be exploited remotely?

CVE-1999-1294 cannot be exploited remotely as it requires local access to the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203