Junglewise Threat Intelligence

CVE-1999-0504: Microsoft Windows NT default or blank password for local accounts

CVE-1999-0504 · Severity: high · CVSS 7.5 · Published 1997-01-01

Executive brief

Microsoft Windows NT systems may contain local user or administrator accounts configured with default, blank, or missing passwords. This allows an unauthorized person to easily log into the system with the privileges of that account. Depending on the account type, this could lead to a complete takeover of the computer, theft of sensitive data, or disruption of business operations.

Technical details

The vulnerability stems from insecure default configurations or administrative oversight where local user or administrator accounts on Windows NT are left with null, blank, or default passwords. This is a credential-based weakness rather than a software bug. An attacker with network or local access can authenticate to the system without providing a valid secret, potentially gaining full administrative control if the affected account has elevated privileges. This issue is typically mitigated by enforcing strong password policies and auditing local account databases for weak credentials.

Affected products

  • Microsoft Windows NT

Timeline

  • 1997-01-01: disclosed

References

Related threats