| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
| A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. |
| .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| The registry in Windows NT can be accessed remotely by users who are not administrators. |
| A system-critical Windows NT file or directory has inappropriate permissions. |
| Windows NT automatically logs in an administrator upon rebooting. |
| The Windows NT guest account is enabled. |
| A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. |
| A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input. |
| ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. |
| A NETBIOS/SMB share password is the default, null, or missing. |
| A NETBIOS/SMB share password is guessable. |
| IP forwarding is enabled on a machine which is not a router or firewall. |
| A Windows NT domain user or administrator account has a default, null, blank, or missing password. |
| A Windows NT domain user or administrator account has a guessable password. |
| A Windows NT local user or administrator account has a default, null, blank, or missing password. |
| A Windows NT local user or administrator account has a guessable password. |
| NETBIOS share information may be published through SNMP registry keys in NT. |