Microsoft Windows 2000 Password Policy Bypass Vulnerability
BID:4256
Info
Microsoft Windows 2000 Password Policy Bypass Vulnerability
| Bugtraq ID: | 4256 |
| Class: | Design Error |
| CVE: |
CVE-2002-0443 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 08 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | This issue was reported to BugTraq by Leonid Mamtchenkov <[email protected]>. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 Password Policy Bypass Vulnerability
Microsoft Windows 2000 allows administrators to set a password policy to enforce the usage of strong passwords. The administrator may specify how long a user's password is valid for and certain requirements for the type of password a user may choose.
When a user's password expires under such a policy, they are forced by Windows 2000 to change it. The policy may be set so that the new password must meet certain requirements to be valid. One of these requirements is that the password does not match one of the previous 18 passwords for that user.
However, it has been found that some aspects of the password policy may be subverted if a user changes their password before it expires and the system prompts them to do so. Specifically, the new password is not checked against the list of user's previous passwords. Under these circumstances, the new password must still meet other requirements of the password policy.
This issue may violate the password policy by allowing a user to recycle recently used passwords when the administrator has made efforts to restrict the user from doing so.
Microsoft Windows 2000 allows administrators to set a password policy to enforce the usage of strong passwords. The administrator may specify how long a user's password is valid for and certain requirements for the type of password a user may choose.
When a user's password expires under such a policy, they are forced by Windows 2000 to change it. The policy may be set so that the new password must meet certain requirements to be valid. One of these requirements is that the password does not match one of the previous 18 passwords for that user.
However, it has been found that some aspects of the password policy may be subverted if a user changes their password before it expires and the system prompts them to do so. Specifically, the new password is not checked against the list of user's previous passwords. Under these circumstances, the new password must still meet other requirements of the password policy.
This issue may violate the password policy by allowing a user to recycle recently used passwords when the administrator has made efforts to restrict the user from doing so.