CVE-1999-0994

Windows NT - Password Hash Cracking via SYSKEY Keystream Reuse

Title source: llm
STIX 2.1

Description

Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/873
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ248183

Scores

EPSS 0.0719
EPSS Percentile 93.7%

Details

CWE
CWE-255
Status published
Products (1)
microsoft/windows_nt 4.0 (4 CPE variants)
Published Dec 16, 1999
Tracked Since Feb 18, 2026