Account Lockout Policy in Windows 2000 Can Be Bypassed
Due to a flaw in NTLM authentication, account lockout policies in Windows 2000 SP 1 can be bypassed.
Steve Manzuik
November 20, 2000
1 Min Read
Reported November 23, 2000 by Microsoft VERSIONS AFFECTED DESCRIPTIONMicrosoft has released a security bulletin, MS00-089, to address an issue with Windows 2000, all versions running SP1. A flaw in the way that NTLM authentication operates in Windows 2000 could allow a domain account lockout policy to be bypassed. VENDOR RESPONSE Microsoft has released a security bulletin, MS00-089 and patches to repair the vulnerability. A patch is available at; http://www.microsoft.com/Downloads/Release.asp?ReleaseID=25606 CREDITDiscovered by Brett Finch |
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like