CVE-1999-1358
Last modified
CVE-1999-1358 is a vulnerability of currently unknown severity. When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows Nt | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-1358?
How severe is CVE-1999-1358?
How do I fix CVE-1999-1358?
Are you affected by CVE-1999-1358?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
