Unrated severityNVD Advisory· Published Jan 5, 1999· Updated Apr 16, 2026
CVE-1999-0391
CVE-1999-0391
Description
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
Affected products
13- cpe:2.3:a:microsoft:terminal_server:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:*+ 10 more
- cpe:2.3:o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:3.5.1:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:3.5.1:sp3:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:3.5.1:sp4:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- marc.infonvd
News mentions
0No linked articles in our index yet.