Junglewise Threat Intelligence

CVE-1999-0519: Microsoft NetBIOS and SMB null or default password on network shares

CVE-1999-0519 · Severity: high · CVSS 7.5 · Published 1997-01-01

Executive brief

A security issue exists where network file shares are protected by default, empty, or missing passwords. This allows anyone on the network to access, modify, or delete files stored on these shared drives without authorization. This can lead to the theft of sensitive company data or the introduction of malicious software into the corporate environment.

Technical details

This vulnerability involves the use of weak or non-existent credentials for NetBIOS/SMB network shares. It is a configuration-based vulnerability where shares are exported with null passwords, default passwords, or no password protection at all. A remote attacker with network access can connect to these shares without authentication or by using well-known default credentials. Successful exploitation allows the attacker to read, write, or delete files on the affected system, potentially leading to full system compromise depending on the permissions of the share. Administrators should enforce strong password policies and ensure that all network shares require authentication.

Affected products

  • Microsoft Windows Networking (NetBIOS/SMB)

Timeline

  • 1997-01-01: disclosed

References

Related threats