PT-2000-1241 · Microsoft · Windows Nt 4.0
Published
2000-04-12
·
Updated
2018-10-12
·
CVE-2000-0259
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows NT 4.0
Description
The issue concerns the default permissions for the CryptographyOffload registry key in Windows NT 4.0, which allows local users to compromise the cryptographic keys of other users. This could potentially lead to unauthorized access to sensitive information.
Recommendations
For Windows NT 4.0, consider restricting access to the CryptographyOffload registry key to prevent local users from compromising the cryptographic keys of other users. As a temporary workaround, restrict permissions on this registry key to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows Nt 4.0