Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
BID:10440
Info
Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
| Bugtraq ID: | 10440 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2004 12:00AM |
| Updated: | May 31 2004 12:00AM |
| Credit: | Discovery of this weakness has been credited to <[email protected]>. |
| Vulnerable: |
Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
Windows 2000 domain controllers are reported prone to a weakness that may permit user accounts with expired passwords to logon to the domain.
This weakness may lead to a security policy violation. Where an administrator expires a users password to force them to modify it, or sets a weak password while creating the account. The user does not modify the password and can still logon to the affected domain. The administrator however believes that the password has been modified.
Windows 2000 domain controllers are reported prone to a weakness that may permit user accounts with expired passwords to logon to the domain.
This weakness may lead to a security policy violation. Where an administrator expires a users password to force them to modify it, or sets a weak password while creating the account. The user does not modify the password and can still logon to the affected domain. The administrator however believes that the password has been modified.
Exploit / POC
Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
Solution:
It is reported that Microsoft has released a hotfix to address this issue. Symantec has not verified this. Customers are advised to contact Microsoft to obtain further information regarding obtaining and applying the appropriate hotfix.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that Microsoft has released a hotfix to address this issue. Symantec has not verified this. Customers are advised to contact Microsoft to obtain further information regarding obtaining and applying the appropriate hotfix.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
References:
References: