Microsoft Web Client Extender NTLM Authentication Vulnerability
BID:2199
Info
Microsoft Web Client Extender NTLM Authentication Vulnerability
| Bugtraq ID: | 2199 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 11 2001 12:00AM |
| Updated: | Jan 11 2001 12:00AM |
| Credit: | Discovered by David Litchfield of @Stake and publicized in a Microsoft Security Bulletin (MS01-001) on January 11, 2001. |
| Vulnerable: |
Microsoft Windows ME Microsoft Windows 2000 Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server Microsoft Office 2000 |
| Not Vulnerable: | |
Exploit / POC
Microsoft Web Client Extender NTLM Authentication Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Web Client Extender NTLM Authentication Vulnerability
Solution:
Microsoft has released the following patches which eliminate this vulnerability:
Microsoft Windows 2000 Professional
Microsoft Windows ME
Microsoft Windows 2000 Advanced Server
Microsoft Office 2000
Microsoft Windows 2000 Server
Solution:
Microsoft has released the following patches which eliminate this vulnerability:
Microsoft Windows 2000 Professional
-
Microsoft Q282132
http://download.microsoft.com/download/win2000platform/Patch/Q282132/N T5/EN-US/Q282132_W2K_SP2_x86_en.EXE
Microsoft Windows ME
-
Microsoft Q282132
http://download.microsoft.com/download/winme/Update/14733/WinMe/EN-US/ 282132USAM.EXE
Microsoft Windows 2000 Advanced Server
-
Microsoft Q282132
http://download.microsoft.com/download/win2000platform/Patch/Q282132/N T5/EN-US/Q282132_W2K_SP2_x86_en.EXE
Microsoft Office 2000
-
Microsoft fpwec
http://download.microsoft.com/download/office2000pro/fpwec/2000/W98NT4 2KMe/EN-US/fpwec.exe
Microsoft Windows 2000 Server