CVE-1999-0372

CVSS 2.0 Score 2.1 of 10 (low)

Details

Published Feb 12, 1999
Updated: Nov 20, 2024
CWE ID 200

Summary

CVE-1999-0372 is a vulnerability affecting the installer for BackOffice Server. The issue arises from the installer failing to delete a setup file named reboot.ini after installation is complete. This file contains account names and passwords in plaintext, posing a significant risk if it falls into the wrong hands. An unauthorized user gaining access to this information could potentially use it to compromise the system by logging in with administrative privileges. This vulnerability highlights the importance of securely handling sensitive information during and after the installation process.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows NT
  • Microsoft Windows 2000
  • Microsoft BackOffice Server

Affected Vendors

  • Microsoft