LiveActive security incident?Get immediate response
CVE Record

CVE-1999-0597: A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hour...

A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

A legacy Windows NT policy weakness lets remote users who are already signed in stay connected past their allowed logon hours instead of being kicked off. In practice, this means a user could keep working, accessing files, or holding a session open outside authorized times, which weakens time-based access controls that management may rely on for shift or contractor boundaries.

Executive priority

Very low priority for modern environments. Only relevant if legacy Windows NT systems remain in scope, in which case the broader risk of running an unsupported OS far outweighs this specific policy gap. Address as part of legacy-system decommissioning rather than a standalone remediation.

Technical view

Windows NT's account policy enforces logon-hour restrictions at authentication time but does not forcibly terminate an established SMB or interactive session when those hours expire. An authenticated remote user retains their session, file handles, and share access beyond the permitted window. There is no CVSS score, no listed CWE, and no vendor patch reference in the bundle; the only external pointer is IBM X-Force entry 1343.

Likely exposure

Extremely limited today. The issue is specific to Windows NT, an operating system that has been out of support for roughly two decades. Exposure only exists in environments still running NT-era servers or emulated legacy systems where logon-hour policies are treated as an active security control.

Exploitation context

Not listed in CISA KEV and no cited source indicates active exploitation. Abuse requires an already-authenticated remote user simply not disconnecting; there is no remote code execution, privilege escalation, or unauthenticated access implied. Impact is a policy-enforcement gap, not a technical compromise vector.

Researcher notes

Historical CVE from 1999 with no CVSS, no CWE mapping, and no affected-version detail in the bundle. Sole third-party reference is IBM X-Force vulnerability 1343. Behavior reflects NT's design where logon-hour policy gated new authentications but did not tear down established sessions; Microsoft later exposed a 'force logoff' policy to address the gap on successor OS versions. Confidence is limited by the sparse source material.

Mitigation direction

  • Retire or isolate any remaining Windows NT systems from production networks.
  • Consult current Microsoft guidance on enforcing logon-hour expiration for the supported OS in use.
  • Enable the modern equivalent policy that forces logoff when logon hours expire.
  • Segment legacy hosts behind firewalls that restrict access to authorized time windows.
  • Monitor session duration on file servers and alert on out-of-hours activity.

Validation and detection

  • Inventory hosts still running Windows NT or NT-derived services and confirm reachability.
  • Review Group Policy or local security settings for 'force logoff when logon hours expire'.
  • Test by authenticating within allowed hours and verifying session termination once the window closes.
  • Check SMB session tables for connections persisting outside assigned schedules.
  • Cross-reference the IBM X-Force entry 1343 and the CVE record for any updated vendor notes.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-1999-0597 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.