Lucene search

K
cve[email protected]CVE-1999-1431
HistoryJan 07, 2005 - 5:00 a.m.

CVE-1999-1431

2005-01-0705:00:00
web.nvd.nist.gov
31
cve-1999-1431
zak
appstation mode
policy bypass
office 97
explorer
software installation
nvd.

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.4%

ZAK in Appstation mode allows users to bypass the “Run only allowed apps” policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

Affected configurations

NVD
Node
microsoftzero_administration_kitMatch1.0

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.4%

Related for CVE-1999-1431