CVE-1999-1452: Low severity Microsoft Windows NT vulnerability
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Where practical, configure policy or require users to log off rather than use 'Lock Workstation' when leaving a machine, to prevent clipboard contents from being exposed via the locked logon prompt.
Windows NT (GINA/interactive logon) Require logoff instead of lock = logoff - Compensating control
Restrict physical access to machines (locked rooms, controlled visitor access, secure desks) to prevent an attacker from gaining the physical access required to exploit the GINA clipboard issue on a locked workstation.
- Operational
Instruct users to clear the clipboard and avoid copying or keeping sensitive information on the clipboard before locking a workstation. Update user guidance/policies and provide training to reinforce this practice.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1452?
CVE-1999-1452 is considered a moderate vulnerability as it requires physical access to the workstation.
How do I fix CVE-1999-1452?
To mitigate CVE-1999-1452, ensure physical security measures are in place to prevent unauthorized access to the workstation.
What systems are affected by CVE-1999-1452?
CVE-1999-1452 affects Microsoft Windows NT version 4.0.
Can CVE-1999-1452 be exploited remotely?
No, CVE-1999-1452 requires physical access to the machine to exploit.
What is the impact of CVE-1999-1452?
The impact of CVE-1999-1452 is that an attacker can view part of the clipboard contents of a locked user's session.