Junglewise Threat Intelligence

CVE-1999-0499: Microsoft Windows NT information disclosure via SNMP registry keys

CVE-1999-0499 · Severity: high · CVSS 7.5 · Published 1997-01-01

Technologies: Microsoft Windows 2000, Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A security issue in older Microsoft Windows NT systems allows sensitive network share information to be exposed through the SNMP service. This could allow an unauthorized person to see details about private file shares and network configurations, potentially leading to unauthorized access to company data. This vulnerability affects the way the system manages network identity and resource sharing.

Technical details

The vulnerability exists in Microsoft Windows NT where NETBIOS share information is inadvertently exposed via SNMP registry keys. An unauthenticated remote attacker can query the SNMP service to enumerate network shares and other system configuration details stored in the registry. This is primarily an information disclosure vulnerability that facilitates further attacks by revealing the internal network structure and available resources. The issue stems from improper access controls or default configurations within the SNMP agent's mapping of registry data.

Affected products

  • Microsoft Windows NT

Timeline

  • 1997-01-01: disclosed: Initial publication date in NVD.

References

Related threats