Junglewise Threat Intelligence

CVE-1999-1217: Microsoft Windows NT privilege escalation via current directory in PATH

CVE-1999-1217 · Severity: medium · CVSS 4.6 · Published 1997-07-25

Technologies: Microsoft Windows Nt. Vendors: Microsoft.

Executive brief

A vulnerability in Windows NT allows local users to gain unauthorized privileges by tricking the system into running malicious code. Because the operating system automatically looks for programs in the current folder before searching system folders, a user can place a malicious file with a common name (like a system utility) in a shared folder. When an administrator or another user attempts to run the legitimate program while in that folder, the malicious version is executed instead, potentially compromising the entire system.

Technical details

The vulnerability stems from the search order used by the Windows API (specifically CreateProcess) and the command shell when resolving executable names. By default, Windows NT searches the current working directory ('.') before searching the system directories or the directories listed in the PATH environment variable. A local attacker with write access to a directory can place a 'Trojan horse' executable with the same name as a common system utility (e.g., cmd.exe or net.exe). When a higher-privileged user executes that command from the compromised directory, the attacker's code runs with the victim's privileges. This is a design-level issue in how the OS handles executable resolution.

Affected products

  • Microsoft Windows NT 4.0 and earlier

Timeline

  • 1997-07-23: disclosed: Initial discussion on NTBugtraq mailing list
  • 1997-07-25: advisory: NVD published date

References

Related threats