Vulnerability Name:

CVE-1999-0886 (CCN-3248)

Assigned:1999-09-17
Published:1999-09-17
Updated:2018-10-12
Summary:The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-16
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-1999-0886

Source: MSKB
Type: UNKNOWN
Q242294

Source: CCN
Type: Microsoft Security Bulletin MS99-041 FAQ
Microsoft Security Bulletin MS99-041: Frequently Asked Questions

Source: CCN
Type: Microsoft Security Bulletin MS01-033
Unchecked Buffer in Index Server ISAPI Extension Could Enable Web Server Compromise

Source: CCN
Type: Microsoft Security Bulletin MS01-041
Malformed RPC Request Can Cause Service Failure

Source: CCN
Type: Microsoft Security Bulletin MS01-044
15 August 2001 Cumulative Patch for IIS

Source: CCN
Type: Microsoft Security Bulletin MS02-001
Trusting Domains Do Not Verify Domain Membership of SIDs in Authorization Data

Source: CCN
Type: Microsoft Security Bulletin MS02-018
Cumulative Patch for Internet Information Services (Q319733)

Source: CCN
Type: Microsoft Security Bulletin MS03-018
Cumulative Patch for Internet Information Service (811114)

Source: CCN
Type: Microsoft Security Bulletin MS99-041
Tool Available for 'RASMAN Security Descriptor' Vulnerability

Source: CCN
Type: OSVDB ID: 1075
Microsoft Windows NT RASMAN Path Subversion Privilege Escalation

Source: BID
Type: UNKNOWN
645

Source: CCN
Type: BID-645
NT RASMAN Privilege Escalation Vulnerability

Source: CCN
Type: Alberto Rodriguez Aragones Web site
Another RASMAN Bug

Source: MS
Type: UNKNOWN
MS99-041

Source: XF
Type: UNKNOWN
nt-rasman-pathname(3248)

Source: CCN
Type: Microsoft Knowledge Base Article 242294
Security Descriptor Allows Privilege Elevation on Remote Computers

Vulnerable Configuration:Configuration 1:
  • cpe:/o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:3.5.1:sp2:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:3.5.1:sp3:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:3.5.1:sp5:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp6:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_nt:3.5.1:sp4:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft windows nt 4.0
    microsoft windows nt 4.0 sp1
    microsoft windows nt 4.0 sp2
    microsoft windows nt 4.0 sp3
    microsoft windows nt 4.0 sp4
    microsoft windows nt 4.0 sp5
    microsoft windows nt 4.0
    microsoft windows nt 3.5.1 sp2
    microsoft windows nt 3.5.1 sp1
    microsoft windows nt 3.5.1 sp3
    microsoft windows nt 3.5.1 sp5
    microsoft windows nt 4.0
    microsoft windows nt 4.0 sp6
    microsoft windows nt 3.5.1 sp4
    microsoft windows 2000 *