CVE-1999-0994Microsoft Windows NT vulnerability

CWE-2553 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
19.4%
top 4.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 30

Description

Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r7rj-gr4g-8x94: Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords2022-04-30
CVEList
CVE-1999-0994: Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords2000-01-18
CVE-1999-0994 — Microsoft Windows NT vulnerability | cvebase