PT-1999-1679 · Microsoft · Windows 2000+1

Publicado

1999-12-31

·

Atualizado

2008-09-05

·

CVE-1999-1358

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Windows NT and Windows 2000
Description: The issue arises when an administrator changes a user policy in Windows NT or Windows 2000, and the policy is not properly updated if the local ntconfig.pol file is not writable by the user. This could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
Recommendations: For Windows NT and Windows 2000, ensure the local ntconfig.pol file is writable by the user to properly update the policy when changes are made by an administrator. As a temporary workaround, consider setting appropriate permissions on the ntconfig.pol file to prevent local users from changing it to read-only.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1358

Produtos afetados

Windows 2000
Windows Nt