Account Lockout Policy in Windows 2000 Can Be Bypassed

Due to a flaw in NTLM authentication, account lockout policies in Windows 2000 SP 1 can be bypassed.

Steve Manzuik

November 20, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported November 23, 2000 by Microsoft

VERSIONS AFFECTED

DESCRIPTIONMicrosoft has released a security bulletin, MS00-089, to address an issue with Windows 2000, all versions running SP1.  A flaw in the way that NTLM authentication operates in Windows 2000 could allow a domain account lockout policy to be bypassed.  

VENDOR RESPONSE

Microsoft has released a security bulletin, MS00-089 and patches to repair the vulnerability.

A patch is available at;

http://www.microsoft.com/Downloads/Release.asp?ReleaseID=25606

CREDITDiscovered by Brett Finch

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like