CVE-1999-0391

Microsoft Terminal Server - Authentication Bypass via SMB Challenge Reuse

Title source: llm
STIX 2.1

Description

The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.

References (1)

Core 1
Core References

Scores

EPSS 0.0489
EPSS Percentile 91.3%

Details

Status published
Products (4)
microsoft/terminal_server
microsoft/windows_2000
microsoft/windows_nt 3.5.1 sp1 (5 CPE variants)
microsoft/windows_nt 4.0 (6 CPE variants)
Published Jan 05, 1999
Tracked Since Feb 18, 2026