Microsoft Windows 2000 Password Policy Bypass Vulnerability

BID:4256

Info

Microsoft Windows 2000 Password Policy Bypass Vulnerability

Bugtraq ID: 4256
Class: Design Error
CVE: CVE-2002-0443
Remote: No
Local: Yes
Published: Mar 08 2002 12:00AM
Updated: Jul 11 2009 11:56AM
Credit: This issue was reported to BugTraq by Leonid Mamtchenkov <[email protected]>.
Vulnerable: Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Server
+ Avaya DefinityOne Media Servers
+ Avaya IP600 Media Servers
+ Avaya S3400 Message Application Server 0
+ Avaya S8100 Media Servers 0
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server
Not Vulnerable:

Discussion

Microsoft Windows 2000 Password Policy Bypass Vulnerability

Microsoft Windows 2000 allows administrators to set a password policy to enforce the usage of strong passwords. The administrator may specify how long a user's password is valid for and certain requirements for the type of password a user may choose.

When a user's password expires under such a policy, they are forced by Windows 2000 to change it. The policy may be set so that the new password must meet certain requirements to be valid. One of these requirements is that the password does not match one of the previous 18 passwords for that user.

However, it has been found that some aspects of the password policy may be subverted if a user changes their password before it expires and the system prompts them to do so. Specifically, the new password is not checked against the list of user's previous passwords. Under these circumstances, the new password must still meet other requirements of the password policy.

This issue may violate the password policy by allowing a user to recycle recently used passwords when the administrator has made efforts to restrict the user from doing so.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report