Vulnerability Description
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
CVSS Score
2.1
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows Nt | All versions |
| Microsoft | Backoffice | 4.0 |
Related Weaknesses (CWE)
References
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ217004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-00
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ217004
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-00
FAQ
What is CVE-1999-0372?
CVE-1999-0372 is a vulnerability with a CVSS score of 2.1 (LOW). The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
How severe is CVE-1999-0372?
CVE-1999-0372 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-0372?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000, Microsoft Windows Nt, Microsoft Backoffice.