CVE-1999-1365
Windows NT - Unprotected User Data Exposure via Home Directory Search Path
Title source: llmDescription
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2336
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/515
Mailing List mailing-list
x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=93069418400856&w=2
Mailing List mailing-list
x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=93127894731200&w=2
Scores
EPSS
0.0194
EPSS Percentile
78.2%
Details
Status
published
Products (1)
microsoft/windows_nt
Published
Jun 28, 1999
Tracked Since
Feb 18, 2026