First published: Fri Dec 31 1999(Updated: )
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | <=4.0 | |
<=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1455 is considered to have a high severity due to the risk of unauthorized access to the RSH service.
To fix CVE-1999-1455, ensure that the RSH service is disabled or properly restrict access according to your security policies.
CVE-1999-1455 affects Microsoft Windows NT versions 3.5 through 4.0.
Yes, CVE-1999-1455 can allow unauthorized users to access the service by logging in from an authorized host.
A common workaround for CVE-1999-1455 is to avoid using the RSH service if possible and to restrict access through network policies.