Microsoft Windows Nt vulnerabilities
201 known vulnerabilities affecting microsoft/windows_nt.
Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20
Vulnerabilities
Page 10 of 11
CVE-2000-0259P4HIGHCVSS 7.2v4.02000-04-12
CVE-2000-0259 [HIGH] CVE-2000-0259: The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Wind
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.
nvd
CVE-1999-1222P4MEDIUMCVSS 5.0v4.01999-12-31
CVE-1999-1222 [MEDIUM] CVE-1999-1222: Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash)
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
nvd
CVE-1999-1452P4LOWCVSS 2.1v4.01999-12-31
CVE-1999-1452 [LOW] CVE-1999-1452: GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard o
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.
nvd
CVE-2002-2401P4LOWCVSS 3.6v4.02002-12-31
CVE-2002-2401 [LOW] CWE-264 CVE-2002-2401: NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permiss
NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.
nvd
CVE-1999-1317P4MEDIUMCVSS 4.6≤ 4.01999-12-31
CVE-1999-1317 [MEDIUM] CVE-1999-1317: Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
nvd
CVE-2002-2028P4LOWCVSS 2.1v4.02002-12-31
CVE-2002-2028 [LOW] CVE-2002-2028: The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has alread
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.
nvd
CVE-2004-0207P4LOWCVSS 2.1v4.02004-11-03
CVE-2004-0207 [LOW] CVE-2004-0207: "Shatter" style vulnerability in the Window Management application programming interface (API) for M
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
nvd
CVE-1999-0717P4LOWCVSS 2.6v4.01999-05-07
CVE-1999-0717 [LOW] CVE-1999-0717: A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
nvd
CVE-2001-1288P4LOWCVSS 2.1v4.02001-07-27
CVE-2001-1288 [LOW] CVE-2001-1288: Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.
nvd
CVE-1999-0585P4LOWCVSS 2.1v3.5.1v4.02000-07-01
CVE-1999-0585 [LOW] CVE-1999-0585: A Windows NT administrator account has the default name of Administrator.
A Windows NT administrator account has the default name of Administrator.
nvd
CVE-2000-0197P4MEDIUMCVSS 4.6v4.02000-02-14
CVE-2000-0197 [MEDIUM] CVE-2000-0197: The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.
nvd
CVE-2001-0373P4LOWCVSS 2.1v4.02001-06-18
CVE-2001-0373 [LOW] CVE-2001-0373: The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dm
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.
nvd
CVE-2002-0725P4MEDIUMCVSS 5.5v4.02002-09-05
CVE-2002-0725 [MEDIUM] CWE-59 CVE-2002-0725: NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage ac
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.
nvd
CVE-1999-0595P4LOWCVSS 2.1v3.5.1v4.02000-01-20
CVE-1999-0595 [LOW] CVE-1999-0595: A Windows NT system does not clear the system page file during shutdown, which might allow sensitive
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
nvd
CVE-1999-0824P4MEDIUMCVSS 4.6v4.01999-11-30
CVE-1999-0824 [MEDIUM] CVE-1999-0824: A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the u
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
nvd
CVE-2000-0089P4LOWCVSS 2.1v4.02000-02-04
CVE-2000-0089 [LOW] CVE-2000-0089: The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive infor
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
nvd
CVE-1999-1294P4LOWCVSS 2.1v3.511999-12-31
CVE-1999-1294 [LOW] CVE-1999-1294: Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherite
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.
nvd
CVE-1999-1364P4LOWCVSS 2.1v4.01999-12-31
CVE-1999-1364 [LOW] CVE-1999-1364: Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode ad
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.
nvd
CVE-1999-1360P4LOWCVSS 2.1v4.01999-12-31
CVE-1999-1360 [LOW] CVE-1999-1360: Windows NT 4.0 allows local users to cause a denial of service via a user mode application that clos
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.
nvd
CVE-1999-1363P4LOWCVSS 2.1v3.5.1v4.01999-12-31
CVE-1999-1363 [LOW] CVE-1999-1363: Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program
Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.
nvd