VYPR
Unrated severityNVD Advisory· Published Sep 17, 1999· Updated Apr 16, 2026

CVE-1999-0886

CVE-1999-0886

Description

The RASMAN security descriptor in Windows NT 4.0 allows unprivileged users to redirect the service executable via the SCM, leading to arbitrary code execution as SYSTEM.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The RASMAN security descriptor in Windows NT 4.0 allows unprivileged users to redirect the service executable via the SCM, leading to arbitrary code execution as SYSTEM.

Vulnerability

The security descriptor (DACL) of the Remote Access Connection Manager service (RASMAN.EXE) in Windows NT 4.0 (Workstation, Server, Enterprise Edition, and Terminal Server Edition) contains an inappropriate Access Control Entry, allowing any unprivileged user with a valid logon to levy requests on the service via the Service Control Manager (SCM). Affected versions include all Windows NT 4.0 variants [1].

Exploitation

An attacker must have a valid user ID and password on the target system. If the machine allows network logon, the vulnerability can be exploited remotely. The attacker uses the SCM to change the executable path of the RASMAN service to point to arbitrary code (which may reside on a remote share). Restarting the service executes the attacker's code in a System context [1].

Impact

Successful exploitation results in arbitrary code execution in the security context of the SYSTEM account, granting the attacker complete control over the affected system. This includes the ability to install programs, view/change/delete data, or create new accounts with full user rights [1].

Mitigation

Microsoft released a tool (not a full patch) that resets the permissions to the appropriate value; it is available from the referenced security bulletin page. The tool should be run against any machine allowing unprivileged interactive or network logons. No Service Pack was available at the time of disclosure, but the tool was placed in the "Hotfixes-PostSP6" folder [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:*
    • (no CPE)

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.