Executive brief
A configuration issue in Windows NT systems prevents the logging of access attempts to sensitive system files and directories. This means that if an unauthorized user modifies or steals critical data, there will be no audit trail for administrators to investigate the breach. This lack of visibility significantly hinders incident response and allows malicious activity to go undetected.
Technical details
This vulnerability relates to an insecure default configuration or failure in the auditing mechanism of Windows NT. The system's file audit policy is not configured to record success or failure events for security-critical files and directories. This is classified as a logging/auditing deficiency (CWE-Other). An attacker can interact with, modify, or delete sensitive system components without generating entries in the security event logs. This lack of forensic evidence allows for persistent unauthorized access and complicates post-compromise recovery efforts. Administrators should manually review and enable auditing for all sensitive system paths.
Affected products
- Microsoft Windows NT NT 4.0 and earlier
Timeline
- 1997-01-01: disclosed: Initial publication date in NVD