PT-1999-1618 · Microsoft · Windows Nt 4.0+1

Publicado

1999-10-26

·

Atualizado

2017-12-19

·

CVE-1999-1234

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Windows NT 4.0
Description The issue allows remote attackers to cause a denial of service. This is achieved by providing a NULL policy handle in a call to functions such as (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo in LSA (LSASS.EXE).
Recommendations For Windows NT 4.0, consider restricting access to the SamrOpenDomain, SamrEnumDomainUsers, and SamrQueryDomainInfo functions until a patch is available. As a temporary workaround, avoid using NULL policy handles in calls to these functions to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1234

Produtos afetados

Lsass.Exe
Windows Nt 4.0