CVE-1999-1294: Low severity Microsoft Windows NT vulnerability
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft/Office Shortcut Bar (OSB)from your environment.Uninstall or remove the Office Shortcut Bar if it is not required on affected systems.
- Configuration
Disable the Office Shortcut Bar to prevent it from enabling backup and restore permissions that are inherited by programs started from the Shortcut Bar.
Office Shortcut Bar (OSB) enabled = false - Operational
Do not launch File Manager or other programs from the Office Shortcut Bar; launch them directly to avoid inheriting backup/restore permissions.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1294?
CVE-1999-1294 has a moderate severity as it allows local users to gain unauthorized access to certain folders.
How do I fix CVE-1999-1294?
To fix CVE-1999-1294, ensure that proper access control and permissions are configured for the Office Shortcut Bar in Windows 3.51.
Who is affected by CVE-1999-1294?
CVE-1999-1294 affects users of Microsoft Windows NT 3.51 who utilize the Office Shortcut Bar.
What type of vulnerability is CVE-1999-1294?
CVE-1999-1294 is a local privilege escalation vulnerability.
Can CVE-1999-1294 be exploited remotely?
CVE-1999-1294 cannot be exploited remotely as it requires local access to the affected system.