NT Blank Password SP4 Vulnerability
BID:227
Info
NT Blank Password SP4 Vulnerability
| Bugtraq ID: | 227 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 08 1999 12:00AM |
| Updated: | Feb 08 1999 12:00AM |
| Credit: | Notice and discussion of this advisory was posted to NTBugtraq by Russ Cooper. |
| Vulnerable: |
Microsoft Windows NT 4.0 SP4 |
| Not Vulnerable: |
Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
Discussion
NT Blank Password SP4 Vulnerability
Windows NT 4.0 SP4 introduced a logic error in the network authentication process for "downlevel" clients. When a user changes his or her password (on an NT 4.0 SP4 server) from a Windows for Workgroups, OS/2, or Macintosh client, the LanMan hash is properly updated, however, the NT hash is reset to a null value. This vulnerability would allow a user to logon to the host or domain from a Win9x or NT machine by presenting the username and a blank password.
Windows NT 4.0 SP4 introduced a logic error in the network authentication process for "downlevel" clients. When a user changes his or her password (on an NT 4.0 SP4 server) from a Windows for Workgroups, OS/2, or Macintosh client, the LanMan hash is properly updated, however, the NT hash is reset to a null value. This vulnerability would allow a user to logon to the host or domain from a Win9x or NT machine by presenting the username and a blank password.