Junglewise Threat Intelligence

CVE-1999-0227: Microsoft Windows NT denial of service in LSASS.EXE

CVE-1999-0227 · Severity: medium · CVSS 5 · Published 1997-06-01

Technologies: Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A vulnerability in the Local Security Authority Subsystem Service (LSASS) of Windows NT can allow an attacker to crash the system remotely. LSASS is a critical component responsible for managing security policies and user authentication. If exploited, this issue results in a denial of service, forcing the operating system to stop functioning and requiring a manual restart.

Technical details

The vulnerability is an access violation within the LSASS.EXE process, specifically affecting the Local Security Authority (LSA) and LSA Remote Procedure Call (LSARPC) interfaces in Windows NT. An attacker can trigger this violation by sending specially crafted requests over the network to the LSARPC service. Successful exploitation causes the LSASS process to terminate unexpectedly, which in turn triggers a system shutdown or hang, resulting in a denial of service. No authentication is required to exploit this flaw. Microsoft addressed this issue in legacy knowledge base article Q154087.

Affected products

  • Microsoft Windows NT

Timeline

  • 1997-06-01: disclosed: Initial publication date

References

Related threats