PT-1999-1679 · Microsoft · Windows 2000+1
Published
1999-12-31
·
Updated
2008-09-05
·
CVE-1999-1358
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Windows NT and Windows 2000
Description:
The issue arises when an administrator changes a user policy in Windows NT or Windows 2000, and the policy is not properly updated if the local ntconfig.pol file is not writable by the user. This could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
Recommendations:
For Windows NT and Windows 2000, ensure the local ntconfig.pol file is writable by the user to properly update the policy when changes are made by an administrator. As a temporary workaround, consider setting appropriate permissions on the ntconfig.pol file to prevent local users from changing it to read-only.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000
Windows Nt