VYPR
Unrated severityNVD Advisory· Published Nov 29, 1999· Updated Apr 16, 2026

CVE-1999-0387

CVE-1999-0387

Description

Windows 95/98 legacy credential caching leaks plaintext network passwords to local attackers with physical access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Windows 95/98 legacy credential caching leaks plaintext network passwords to local attackers with physical access.

Vulnerability

The vulnerability resides in a legacy RAM-based credential caching mechanism carried forward from Windows for Workgroups into Windows 95 and Windows 98 [1]. Although this mechanism is not used by either operating system, it persists and stores the plaintext network password of the last user who established a network session. The affected versions are Windows 95 and Windows 98; Windows 98 Second Edition is not vulnerable [1].

Exploitation

An attacker must have physical access to the target machine, and the machine must not have been rebooted since the last networking session [1]. With physical access, the attacker can query the legacy credential cache to retrieve the plaintext network credentials of the last user who logged onto the network [1].

Impact

Successful exploitation allows the attacker to read the plaintext network password of the last user to perform network access on the machine [1]. This leads to a direct disclosure of credentials, which can then be used to impersonate the user and gain unauthorized access to network resources [1]. The compromise is limited to the password cached in memory and does not immediately grant elevated privileges on the local system beyond the user's network identity.

Mitigation

Microsoft released a security patch for this vulnerability, described in Microsoft Security Bulletin MS99-052 [1]. The patch eliminates the cached plaintext credentials. Windows 98 Second Edition is not affected by this vulnerability [1]. No further workarounds are documented in the available references.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Microsoft/Windows2 versions
    cpe:2.3:o:microsoft:windows_95:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_95:*:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*
    • (no CPE)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.