VYPR
Unrated severityNVD Advisory· Published Jul 6, 1999· Updated Apr 16, 2026

CVE-1999-0728

CVE-1999-0728

Description

Local user can disable keyboard and mouse on Windows NT 4.0 via unprotected IOCTLs, causing denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local user can disable keyboard and mouse on Windows NT 4.0 via unprotected IOCTLs, causing denial of service.

Vulnerability

The vulnerability exists in Windows NT 4.0 (all editions) where IOCTLs to keyboard and mouse drivers do not require administrative privileges. A user-level program can call these IOCTLs to disable input devices. Affected versions: Windows NT Workstation 4.0, Server 4.0, Server 4.0 Enterprise Edition, and Terminal Server Edition [1].

Exploitation

An attacker needs local access to the system with a standard user account. They can run a program that makes direct IOCTL calls to disable the keyboard or mouse. No special authentication beyond user-level access is required [1].

Impact

Successful exploitation results in denial of service: the keyboard and mouse become non-functional. The machine must be rebooted to restore normal service. On Terminal Server, only the console keyboard and mouse are affected [1].

Mitigation

Microsoft released a patch in July 1999, as detailed in Security Bulletin MS99-024 [1]. The patch is available for all affected Windows NT 4.0 versions. No workaround is documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5
  • cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp1:enterprise:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*
    • (no CPE)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.