ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
An application-critical Windows NT registry key has inappropriate permissions.
An application-critical Windows NT registry key has an inappropriate value.
The OS/2 or POSIX subsystem in NT is enabled.
A system-critical Windows NT registry key has an inappropriate value.
In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
A Windows NT log file has an inappropriate maximum size or retention period.
A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.
The Logon box of a Windows NT system displays the name of the last user who logged in.
A system does not present an appropriate legal message or warning to a user who is accessing it.
An event log in Windows NT has inappropriate access permissions.
A system-critical Windows NT registry key has inappropriate permissions.
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
The HKEYLOCALMACHINE key in a Windows NT system has inappropriate, system-critical permissions.
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
The HKEYCLASSESROOT key in a Windows NT system has inappropriate, system-critical permissions.
There is a one-way or two-way trust relationship between Windows NT domains.
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
A system-critical Windows NT file or directory has inappropriate permissions.
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
IP forwarding is enabled on a machine which is not a router or firewall.
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.