Originally Posted: January 21, 2000
Revised: February 4, 2000
On January 21, 2000, Microsoft released the original version of this bulletin, discussing a security vulnerability in a Microsoft® Windows NT 4.0 administrative utility. The original version of the bulletin discussed the vulnerability within the context of Windows NT 4.0 Server, Terminal Server Edition. However, we have since learned of scenarios under which the vulnerability could also affect Windows NT 4.0 servers and workstations, and have revised the bulletin accordingly.
The utility creates a temporary file during execution that can contain security-sensitive information, but does not appropriately restrict access to it. Under certain conditions, it could be possible for a malicious user to read the file as it was being created
Frequently asked questions regarding this vulnerability can be found at http://www.microsoft.com/technet/security/bulletin/fq00-004.mspx.
Please see the following references for more information related to this issue.
| • | Frequently Asked Questions: Microsoft Security Bulletin MS00-004, http://www.microsoft.com/technet/security/bulletin/fq00-004.mspx. |
| • | Microsoft Knowledge Base (KB) article 249108, Registry Data Is Viewable By All Users After Rdisk Repair Update, http://support.microsoft.com/default.aspx?scid=kb;en-us;249108. |
| • | Microsoft Knowledge Base (KB) article 156328, Description of Windows NT Emergency Repair Disk, http://support.microsoft.com/default.aspx?scid=kb;en-us;156328 |
| • | Microsoft Security web site, |
Obtaining Support on this Issue
This is a fully supported patch. Information on contacting Microsoft Technical Support is available at http://support.microsoft.com/contactussupport/?ws=support.
Acknowledgments
Microsoft thanks Arne Vidstrom (http://ntsecurity.nu) for reporting this issue to us and working with us to protect customers.
Revisions
| • | January 21, 2000: Bulletin Created. |
| • | February 4, 2000: Bulletin revised to address other affected versions |
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.