CVE-1999-1316: High severity Microsoft Windows NT vulnerability
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure or replace the password filter so it rejects passwords that contain the user's account name — prevent users from creating passwords that include their name.
Windows NT (passfilt.dll) reject_passwords_containing_username = true - Compensating control
Enforce stronger password policies centrally or via administrative procedures (minimum complexity, manual checks or account-name checks) to prevent use of account names in passwords until an official fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1316?
CVE-1999-1316 is considered a low severity vulnerability.
How does CVE-1999-1316 affect password security?
CVE-1999-1316 allows users to create passwords containing their own names, making it easier for attackers to guess passwords.
Who is affected by CVE-1999-1316?
CVE-1999-1316 affects users of Microsoft Windows NT 4.0 SP2, specifically those utilizing the Passfilt.dll feature.
What is the recommended action to mitigate CVE-1999-1316?
To mitigate CVE-1999-1316, users are advised to avoid using their names in passwords and update to a later version of Windows NT that addresses this issue.
Is there a patch available for CVE-1999-1316?
There is no specific patch for CVE-1999-1316, but upgrading to a more secure version of Windows is recommended.