VulnerabilityModified
CVE-1999-1317
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
MEDIUM 4.6EPSS 1.82%
Does this matter?
Lower severity and a low EPSS score (1.82%). Track it; it rarely justifies an emergency change on its own.
Description
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows nt
- Source
- cve@mitre.org
References
- http://marc.info/?l=ntbugtraq&m=92127046701349&w=2
- http://marc.info/?l=ntbugtraq&m=92162979530341&w=2
- http://support.microsoft.com/support/kb/articles/q222/1/59.aspPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7398
- http://marc.info/?l=ntbugtraq&m=92127046701349&w=2
- http://marc.info/?l=ntbugtraq&m=92162979530341&w=2
- http://support.microsoft.com/support/kb/articles/q222/1/59.aspPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7398
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.