CVE-1999-0886

Windows NT Service Control Manager - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0886. PoCs published by Alberto Rodríguez Aragonés.

AI-analyzed exploit summary This exploit leverages a registry modification vulnerability in Windows NT to replace the RASMAN service binary path with a malicious executable. When the RAS service restarts, the trojan service runs with SYSTEM privileges, enabling privilege escalation or remote command execution.

Description

The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alberto Rodríguez Aragonés · textlocalwindows
https://www.exploit-db.com/exploits/19502

This exploit leverages a registry modification vulnerability in Windows NT to replace the RASMAN service binary path with a malicious executable. When the RAS service restarts, the trojan service runs with SYSTEM privileges, enabling privilege escalation or remote command execution.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows NT (RAS Service)
Auth required
Prerequisites: Authenticated domain user access · Ability to modify registry keys · RAS Service restart
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ242294
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/645

Scores

EPSS 0.2157
EPSS Percentile 97.4%

Details

CWE
CWE-16
Status published
Products (1)
microsoft/windows_nt 4.0 (6 CPE variants)
Published Sep 17, 1999
Tracked Since Feb 18, 2026