Junglewise Threat Intelligence

CVE-1999-0534: Microsoft Windows NT excessive user privileges assignment

CVE-1999-0534 · Severity: medium · CVSS 4.6 · Published 1997-01-01

Technologies: Microsoft Windows 2000, Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A configuration issue in Windows NT allows standard users to be granted excessive administrative privileges. This could allow an individual with local access to perform sensitive actions such as bypassing security audits, modifying system files, or taking ownership of data they should not be able to access. Such misconfigurations can lead to a total compromise of the workstation or server's integrity and confidentiality.

Technical details

This vulnerability describes a state of excessive privilege assignment within the Windows NT operating system. Users may be granted sensitive rights including, but not limited to, 'Act as part of the operating system', 'Debug programs', 'Take ownership of files or other objects', and 'Load and unload device drivers'. An attacker with local access and these privileges can bypass security descriptors, escalate their authority to SYSTEM level, or interfere with kernel-mode operations. The root cause is typically insecure default configurations or administrative errors in User Rights Assignment. Remediation involves auditing and restricting user rights via the User Manager or Group Policy to follow the principle of least privilege.

Affected products

  • Microsoft Windows NT

Timeline

  • 1997-01-01: disclosed

References

Related threats