CVE-1999-1431

ZAK - Auth Bypass

Title source: llm
STIX 2.1

Description

ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Satu Laksela · textlocalwindows
https://www.exploit-db.com/exploits/19144

References (3)

Core 3
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/181
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=91576100022688&w=2
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=91606260910008&w=2

Scores

EPSS 0.0090
EPSS Percentile 75.9%

Details

Status published
Products (1)
microsoft/zero_administration_kit 1.0
Published Jan 07, 2005
Tracked Since Feb 18, 2026