CVE-1999-1360: Low severity Microsoft Windows NT vulnerability
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict local interactive and non‑administrative logons to trusted accounts and enforce least privilege so unprivileged users cannot run arbitrary user‑mode applications that could trigger the issue. Use host-based access controls, group policy, or account management to remove or disable unnecessary local accounts.
- Operational
Monitor Microsoft security advisories for an official patch or update addressing this Windows NT kernel handle closure crash and apply vendor-supplied fixes when they become available. Meanwhile, ensure critical services are redundant and prepare procedures to recover or restart systems affected by the denial-of-service condition.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1360?
CVE-1999-1360 is considered a high severity vulnerability due to its potential to cause denial of service on Windows NT 4.0.
How do I fix CVE-1999-1360?
To mitigate CVE-1999-1360, it is recommended to upgrade to a newer version of Windows that is not affected by this vulnerability.
Who is affected by CVE-1999-1360?
CVE-1999-1360 affects all local users of Windows NT 4.0.
What type of attack does CVE-1999-1360 involve?
CVE-1999-1360 involves a local denial of service attack executed through a user mode application.
What are the potential impacts of CVE-1999-1360?
The potential impact of CVE-1999-1360 is a system crash when the kernel attempts to close a handle opened by a user mode application.