CVE detail
CVE-1999-1358 — CVE-1999-1358
Published 1999-12-31 · Modified 2026-06-16 · Vendor microsoft · Product windows_2000 · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0141
EPSS probability
exploitation probability, 30d
70.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References