Junglewise Threat Intelligence

CVE-1999-0572: Microsoft Windows NT Registry Editor file association vulnerability

CVE-1999-0572 · Severity: critical · CVSS 9.3 · Published 1997-01-01

Executive brief

A security issue in Windows NT allows the system to automatically execute registry configuration files (.reg) using the Registry Editor. If a user is tricked into opening a malicious file, an attacker can gain full control over the system's configuration and settings. This could lead to total system compromise, data theft, or the installation of persistent malicious software.

Technical details

The vulnerability stems from the default file association of the .reg extension with the Windows Registry Editor (regedit.exe) in Windows NT. When a user opens a .reg file, the system automatically imports the contained registry keys and values without sufficient warning or isolation. An attacker can exploit this by delivering a malicious .reg file via email or web download (social engineering). Successful exploitation allows the attacker to modify critical system settings, disable security features, or ensure the execution of malicious code upon the next system boot. This is classified as a Trojan Horse attack vector due to the reliance on user interaction to execute the file.

Affected products

  • Microsoft Windows NT NT 4.0 and earlier

Timeline

  • 1997-01-01: disclosed

References

Related threats