9
CVSSv2

CVE-1999-0886

Published: 17/09/1999 Updated: 07/11/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows nt 4.0

Exploits

source: wwwsecurityfocuscom/bid/645/info Any authenticated NT user (ie domain user) can modify the pathname for the RASMAN binary in the Registry The next time the RAS Service is started, the (trojan) service referenced by the RASMAN pathname will be executed with system privileges This trojan service may allow the User to execute comma ...