SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-1999-1431

ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such…

MEDIUM 4.6EPSS 9.65%

Does this matter?

Lower severity and a low EPSS score (9.65%). Track it; it rarely justifies an emergency change on its own.

Description

ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
9.65% probability · 95th percentile
CISA KEV
Not listed
Affected
microsoft/zero administration kit
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.