CVE-1999-0504 describes a vulnerability in Windows NT where local user or administrator accounts are configured with default, null, blank, or missing passwords. This misconfiguration allows unauthorized users to gain access to the system without authentication, as the accounts are left unprotected by a password.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains the Metasploit 'psexec' exploit module for Windows SMB. The module enables authenticated remote code execution on Windows systems by leveraging valid administrator credentials (username/password or NTLM hash) over the SMB protocol (typically port 445/tcp). The exploit mimics the functionality of SysInternals' PsExec tool, uploading and executing an arbitrary payload (such as a reverse shell or Meterpreter) on the target. It supports multiple payload delivery methods, including PowerShell, native executable upload, MOF upload, and direct command execution. The module is highly weaponized, allowing for flexible payload selection and automated cleanup. The only file in the repository is a Ruby script structured as a Metasploit module, making use of several Metasploit mixins for SMB interaction, payload handling, and reporting. The exploit targets any Windows system with SMB enabled and accessible, provided the attacker has valid administrative credentials.
This repository contains a single Metasploit module: 'modules/exploits/windows/local/wmi.rb'. The module exploits Windows Management Instrumentation (WMI) to achieve remote command execution on Windows hosts. It leverages the current user's credentials or supplied credentials to execute a PowerShell payload on the target system, using WMI over TCP port 135 (and an ephemeral port for RPC). The exploit is similar in effect to psexec but does not require explicit password or hash knowledge if running from an existing session. The module is highly weaponized, supporting custom payloads (typically Meterpreter) and cleanup of artifacts (environment variables in the registry). The main fingerprintable endpoints are TCP port 135 (WMI/RPC) and the Windows registry path for environment variables. The exploit targets any Windows system with WMI enabled and accessible, and is referenced against CVE-1999-0504 (Administrator with no password). The code is written in Ruby and is designed to be used within the Metasploit framework.
This repository contains a single Metasploit module: 'PsExec via Current User Token' (modules/exploits/windows/local/current_user_psexec.rb). The module enables an attacker with a Meterpreter session on a Windows system to execute arbitrary code on remote Windows systems by creating a service using the current user's authentication token. It does not require password or hash credentials, leveraging the existing session's privileges. The exploit works by uploading a payload (either as an executable or PowerShell command), creating a network share to host the payload, and then creating and starting a service on each target system that executes the payload via a UNC path. After execution, the service and share are cleaned up. The module supports both SMB and PowerShell techniques and can target multiple hosts specified by the attacker. The main attack vectors are local (requires an existing session) and network (spreads to other systems via service creation and SMB/UNC paths). The module is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The only file in the repository is the exploit module itself, written in Ruby.
This repository contains a single Metasploit module: 'Powershell Remoting Remote Command Execution' (modules/exploits/windows/local/powershell_remoting.rb). The module targets Microsoft Windows systems with PowerShell Remoting enabled (typically on TCP port 47001). It allows an attacker to execute arbitrary payloads (such as Meterpreter or shell) on remote systems by leveraging PowerShell Remoting. The attacker can specify targets via an IP address range (RHOSTS) or a file containing hostnames (HOSTFILE). Authentication can be provided via SMBUser, SMBPass, and SMBDomain options. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The main attack vector is network-based, exploiting remote command execution capabilities over PowerShell Remoting. The module references CVE-1999-0504, which relates to Windows systems with default or no administrator password, but the exploit is generally applicable to any system with PowerShell Remoting enabled and accessible.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.