The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
A system-critical Windows NT registry key has an inappropriate value.
In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.
A Windows NT log file has an inappropriate maximum size or retention period.
A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
The OS/2 or POSIX subsystem in NT is enabled.
The Logon box of a Windows NT system displays the name of the last user who logged in.
An application-critical Windows NT registry key has inappropriate permissions.
The HKEYLOCALMACHINE key in a Windows NT system has inappropriate, system-critical permissions.
A system does not present an appropriate legal message or warning to a user who is accessing it.
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
The HKEYCLASSESROOT key in a Windows NT system has inappropriate, system-critical permissions.
An application-critical Windows NT registry key has an inappropriate value.
An event log in Windows NT has inappropriate access permissions.
A system-critical Windows NT registry key has inappropriate permissions.
There is a one-way or two-way trust relationship between Windows NT domains.
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
A system-critical Windows NT file or directory has inappropriate permissions.
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.