First published: Fri Dec 31 1999(Updated: )
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1359 is considered a moderate vulnerability since it can allow users to bypass certain security policies.
To fix CVE-1999-1359, ensure that server names do not exceed 13 characters to enforce policy restrictions properly.
CVE-1999-1359 affects all versions of Microsoft Windows NT that utilize the Ntconfig.pol file.
The risks associated with CVE-1999-1359 include unauthorized access or privilege escalation due to bypassed policy restrictions.
Users with access to a server whose name exceeds 13 characters can exploit CVE-1999-1359 to bypass security policies.