Junglewise Threat Intelligence

CVE-1999-0575: Microsoft Windows NT missing security audit logging policy

CVE-1999-0575 · Severity: high · CVSS 7.5 · Published 1997-01-01

Technologies: Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A configuration issue in Windows NT systems allows the operating system to operate without logging critical security events. This means that unauthorized activities, such as failed login attempts, file access, or system shutdowns, are not recorded in the audit logs. In the event of a security breach, administrators would have no forensic trail to identify how the system was compromised or what data was accessed.

Technical details

This vulnerability stems from a failure to enable or enforce a comprehensive user audit policy within Windows NT. The system fails to generate log entries for success or failure events across multiple categories: Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and Process Tracking. This lack of visibility allows attackers to perform reconnaissance, lateral movement, and administrative changes without leaving a trace in the local security event logs. While primarily a configuration-based weakness, it is classified as a high-severity issue due to the complete loss of accountability and forensic capability on the affected host.

Affected products

  • Microsoft Windows NT NT 4.0 and earlier

Timeline

  • 1997-01-01: disclosed: NVD Published Date

References

Related threats