Junglewise Threat Intelligence

CVE-1999-0249: Microsoft Windows NT arbitrary command execution in RSHSVC

CVE-1999-0249 · Severity: high · CVSS 7.2 · Published 1997-01-01

Technologies: Microsoft Windows 2000, Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows NT Remote Shell service (RSHSVC) allows users to execute unauthorized commands on the system. This could lead to a complete compromise of the server, including the theft of sensitive data or the disruption of critical operations. Organizations still running legacy Windows NT systems are at risk of local attackers gaining full administrative control.

Technical details

The RSHSVC program in Microsoft Windows NT contains a vulnerability that allows for arbitrary command execution. While the NVD CVSS v2.0 vector suggests a local attack vector (AV:L), the historical description indicates that remote users may be able to trigger the flaw. An attacker exploiting this vulnerability can achieve full system compromise, represented by complete loss of confidentiality, integrity, and availability. This is a legacy vulnerability affecting the Remote Shell service component of the operating system.

Affected products

  • Microsoft Windows NT

Timeline

  • 1997-01-01: disclosed

References

Related threats